Description
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Published: 2026-09-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM Guardium Data Protection version 12.2 contains an insecure deserialization flaw that allows a remote unauthenticated attacker to execute arbitrary code. The vulnerability is triggered when the system processes untrusted data during normal operation and does not adequately validate or sanitize the serialized payload. The flaw is classified as CWE‑502, which is a vulnerability arising from improper handling of untrusted input during deserialization. Successful exploitation enables direct remote code execution, giving an attacker full control over the host running Guardium.

Affected Systems

The affected product is IBM Guardium Data Protection 12.2 on Linux environments. The specific fix applies to the release identified by the fix ID SqlGuard_12.0p233 in the IBM Fix Central catalog. Earlier releases prior to 12.2 or other products are not listed in the CVE entry, so they are not impacted according to this advisory.

Risk and Exploitability

The CVSS score of 9.8 places this vulnerability in the Critical range, indicating a very high severity. The EPSS score is not available, so current exploitation frequency cannot be quantified. The attack vector is remote and requires no authentication, allowing an attacker to execute arbitrary code and compromise confidentiality, integrity, and availability of the host running Guardium. The vulnerability is not listed in the CISA KEV catalog and, due to the lack of existing mitigations, represents a significant risk. Organizations should treat this issue as a high‑priority security concern.

Generated by OpenCVE AI on September 19, 2026 at 11:56 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium Data Protection 12.2 fixpack (SqlGuard_12.0p233) from the IBM Fix Central repository to remediate the insecure deserialization logic.
  • Restart the Guardium services or reboot the appliance so that the updated code is loaded into memory.
  • Limit external network exposure by allowing inbound connections to the Guardium appliance only from authorized IP addresses until the patch is deployed.

Generated by OpenCVE AI on September 19, 2026 at 11:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-502
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T19:27:48.854Z

Reserved: 2026-08-27T09:52:12.824Z

Link: CVE-2026-81657

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T20:17:23.997

Modified: 2026-09-18T20:17:23.997

Link: CVE-2026-81657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:00:08Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data