Description
IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reassembly buffer, potentially resulting in denial of service or arbitrary code execution on the affected system.
Published: 2026-10-08
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.x is susceptible to a heap‑based buffer overflow in the S‑TAP TrafficTap TDS login reassembly. An unauthenticated remote attacker can craft TDS login fragments that exceed the fixed‑size reassembly buffer, leading to either a denial‑of‑service condition or arbitrary code execution on the affected system. This flaw falls under CWE‑119 and directly undermines the confidentiality or integrity of the protected data.

Affected Systems

The vulnerability applies to IBM Guardium Data Protection versions 12.0, 12.1, 12.2, and 12.3 running on Windows. All these releases are affected by the heap overflow in the S‑TAP TrafficTap service.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score is not available. The flaw is listed outside the CISA KEV catalog. Based on the description, the attack vector is likely via unauthenticated remote network traffic that reaches the S‑TAP TrafficTap interface. The exploit requires an attacker to send specially crafted TDS login fragments, a straightforward task given the lack of authentication or pattern verification in the reassembly routine. Successful exploitation can crash the service or allow arbitrary code execution, representing a significant threat for systems that host Guardium Data Protection.

Generated by OpenCVE AI on October 8, 2026 at 20:37 UTC.

Remediation

Vendor Solution

For all affected versions, IBM strongly recommends addressing these vulnerabilities now by applying the latest IBM Guardium Data Protection Windows S-TAP patch:  https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=All&platform=All&function=fixId&fixids=Guardium_12.x.p101_r120203346_S-TAP_Windows&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium Data Protection Windows S‑TAP patch for all affected versions as published in the IBM Support Fix Central.
  • Restrict inbound traffic on the S‑TAP TrafficTap port to trusted IP ranges or internal networks to limit exposure to unauthenticated requests.
  • Configure network or firewall rules to segment or isolate Guardium Data Protection servers from untrusted external sources, thereby reducing the attack surface for this buffer overflow.

Generated by OpenCVE AI on October 8, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reassembly buffer, potentially resulting in denial of service or arbitrary code execution on the affected system.
Title IBM Guardium Data Protection Buffer Overflow
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-119
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T19:11:17.824Z

Reserved: 2026-08-28T16:17:09.587Z

Link: CVE-2026-82344

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T20:17:37.020

Modified: 2026-10-08T20:49:50.083

Link: CVE-2026-82344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:00:11Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer