Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 exposes a missing authorization check within its REST API, allowing an authenticated user to execute requests that should be restricted to privileged roles. The flaw is a classic example of missing access control (CWE‑862). An attacker who can authenticate to the API can therefore elevate privileges by invoking protected endpoints, potentially gaining the ability to alter configuration or view protected data. No further specific administrative actions are claimed in the official description, and the impact is limited to what elevated roles normally possess.

Affected Systems

The vulnerability affects IBM Guardium Data Protection version 12.2, specifically build 12.2.0 as identified by IBM. The vendor fix package, SqlGuard_12.0p233_FixPack, addresses the issue for this release.

Risk and Exploitability

The CVSS score of 8.8 classifies the problem as high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, an attacker with valid credentials can send crafted requests to endpoints that lack proper authorization checks, thereby escalating privileges. The risk is proportional to the exposure space of the REST API within the operating environment.

Generated by OpenCVE AI on September 19, 2026 at 12:56 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Upgrade IBM Guardium Data Protection to version 12.2.0 or later, applying the official fix pack (SqlGuard_12.0p233_FixPack) as provided by IBM.
  • Restrict access to the REST API by implementing network segmentation or firewall rules so that only trusted hosts can reach it, and enforce least‑privilege principles for API credentials.
  • Review and enforce role‑based access controls in the Guardium administration console, ensuring that only administrators can perform privileged actions, and monitor for anomalous API usage regularly.

Generated by OpenCVE AI on September 19, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-862
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T03:55:47.883Z

Reserved: 2026-08-31T09:02:30.446Z

Link: CVE-2026-82885

cve-icon Vulnrichment

Updated: 2026-09-19T14:05:51.863Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:24.770

Modified: 2026-10-06T15:37:39.083

Link: CVE-2026-82885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses