Description
IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance.
Published: 2026-09-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from an insecure deserialization flaw combined with attacker‑controlled reflective method dispatch in IBM Guardium Data Protection’s Change Audit System listener. An attacker can supply crafted serialized messages over the network, causing the appliance to execute arbitrary code. The weakness is categorized as CWE-94 and can lead to total compromise of the Guardium appliance, including data access, tampering and service disruption.

Affected Systems

IBM Guardium Data Protection version 12.2 on platforms that expose TCP port 16017 is affected. The fix is available through IBM FixCentral for the 12.2 release. No other versions are listed as vulnerable in the current data.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. While EPSS data is not available, the vulnerability remains unlisted in the CISA KEV catalog. An attacker with network access to port 16017 could exploit the flaw without prior authentication, making the attack surface open to any host that can reach the appliance.

Generated by OpenCVE AI on September 19, 2026 at 11:34 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM FixCentral update for Guardium Data Protection 12.2 to remove the insecure deserialization flaw.
  • Restrict TCP port 16017 to trusted networks or hosts, or filter traffic to the Change Audit System listener.
  • Continuously monitor the appliance for unexpected serialized traffic or unauthorized code execution events.

Generated by OpenCVE AI on September 19, 2026 at 11:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:39.548Z

Reserved: 2026-08-28T16:06:21.872Z

Link: CVE-2026-82340

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T20:17:24.517

Modified: 2026-09-18T20:17:24.517

Link: CVE-2026-82340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T11:45:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')