Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.
Published: 2026-09-18
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 contains an input validation flaw that fails to neutralize user-supplied data before embedding it into web page output. This missing sanitization allows a remote authenticated attacker to inject arbitrary JavaScript that executes in the victim’s browser, potentially enabling credential theft, session hijacking, or other actions performed under the compromised account. The weakness aligns with CWE‑79.

Affected Systems

The vulnerability affects IBM Guardium Data Protection version 12.2 running on Linux. All installations of the 12.2 release are impacted until the FixPack SqlGuard_12.0p233 is applied. No other product versions were reported to be affected.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. An EPSS score is not available, so the current probability of exploitation remains unknown. Because the flaw requires authentication, an attacker must first obtain valid Guardium web interface credentials before injecting code, which limits the attack surface. The vulnerability is not listed in the CISA KEV catalog, and no public exploitation evidence is known. If credentials are compromised, the attacker could run arbitrary JavaScript with the privileges of the authenticated user, potentially escalating privileges or spreading the compromise to other systems.

Generated by OpenCVE AI on September 19, 2026 at 11:54 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the latest FixPack (SqlGuard_12.0p233) to IBM Guardium Data Protection 12.2 as released by IBM.
  • Restart the Guardium Data Protection services so that the updated code is loaded.
  • Implement a strict Content Security Policy on the web interface to restrict JavaScript execution as a temporary measure until the patch is deployed.

Generated by OpenCVE AI on September 19, 2026 at 11:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T20:15:16.301Z

Reserved: 2026-08-31T09:09:19.458Z

Link: CVE-2026-82890

cve-icon Vulnrichment

Updated: 2026-09-18T20:15:09.490Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:25.020

Modified: 2026-10-06T15:38:05.950

Link: CVE-2026-82890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')