Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Published: 2026-09-18
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 has an improper neutralization of input during web page generation that permits a remote authenticated attacker to execute arbitrary code. The vulnerability is a classic example of injection leading to code execution, classified as CWE‑79, and can compromise the confidentiality, integrity, and availability of the protected data if exploited.

Affected Systems

The affected product is IBM Guardium Data Protection version 12.2, including releases 12.2.0 and later build numbers for the Linux platform, as identified by the provided CPE strings.

Risk and Exploitability

With a CVSS score of 9, this issue is considered critical. The EPSS score is not available, and the vulnerability is not yet listed in CISA KEV, indicating no known active exploitation at time of reporting. The attack requires remote authentication to the Guardium web interface, making it a high‑risk threat for systems that allow unauthenticated or weakly authenticated access to their web console.

Generated by OpenCVE AI on September 19, 2026 at 13:38 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Download and apply the IBM Guardium Data Protection 12.2 fix pack from IBM Fix Central, ensuring the system runs the latest secure release.
  • Reconfigure the Guardium web administration console to limit authentication and enforce strong password or multi‑factor authentication before granting access to any web interface.
  • Validate that input handling and output escaping are correctly implemented by verifying that the web pages no longer reflect injected content, thereby mitigating code execution via page generation.

Generated by OpenCVE AI on September 19, 2026 at 13:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T20:15:43.834Z

Reserved: 2026-09-01T02:03:38.278Z

Link: CVE-2026-84031

cve-icon Vulnrichment

Updated: 2026-09-18T20:15:39.549Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:26.060

Modified: 2026-10-06T15:39:10.387

Link: CVE-2026-84031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:15:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')