Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.
Published: 2026-09-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Directory Traversal
Action: Immediate Patch
AI Analysis

Impact

A path traversal flaw in IBM Guardium Data Protection 12.2 allows a remote authenticated attacker to request files outside the intended directory structure, potentially exposing sensitive system files or configuration data. The weakness is classified as CWE-22, indicating that the software incorrectly validates or normalizes path input, enabling the attacker to read or, depending on the target file, compromise confidentiality. The description does not mention arbitrary code execution, so the primary impact is limited to unauthorized file access.

Affected Systems

IBM Guardium Data Protection version 12.2, deployed on Linux. No other versions are listed as affected in the current advisory.

Risk and Exploitability

The CVSS score of 7.6 places the issue in the high severity range. EPSS data is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is remote, but an authenticated session is required, meaning compromise of valid credentials is a prerequisite. Attackers can exploit the flaw by delivering a crafted request containing traversal sequences to vulnerable endpoints, thereby gaining read access to arbitrary files on the host.

Generated by OpenCVE AI on September 19, 2026 at 11:30 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply IBM Guardium Data Protection 12.2 fix pack available from IBM's support site to eliminate the path traversal flaw.
  • Ensure that only minimal privilege accounts are allowed to authenticate against Guardium, and enforce strict access controls to sensitive directories and configuration files.
  • If a patch cannot be applied immediately, isolate the Guardium appliance behind a firewall, permitting access only from trusted networks and monitoring for anomalous requests.
  • After remediation, perform vulnerability scanning and verify that the path traversal endpoint no longer accepts traversing inputs.

Generated by OpenCVE AI on September 19, 2026 at 11:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:38.555Z

Reserved: 2026-08-31T09:18:49.725Z

Link: CVE-2026-82896

cve-icon Vulnrichment

Updated: 2026-09-19T14:05:02.970Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:25.393

Modified: 2026-10-06T15:38:45.477

Link: CVE-2026-82896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')