Description
IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Internal Database via Hardcoded Credentials
Action: Immediate Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 contains a hardcoded credentials flaw in the hardware_assess/obstore binaries. A low‑privileged authenticated user can extract the product master secrets, enabling an attacker to authenticate to the internal database as a privileged entity and compromise sensitive system data. The vulnerability is a classic insecure credential issue (CWE-798).

Affected Systems

IBM Guardium Data Protection 12.2 running on Linux is affected. The fix is available through IBM Fix Central and is linked in the advisory. No other versions or platforms are listed as impacted in the current data.

Risk and Exploitability

The CVSS score of 8.8 classifies the issue as high severity. The EPSS score of <1% indicates a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is local and authenticated; an attacker with low‑privileged credentials must execute the hardware_assess/obstore binaries to recover the hardcoded master secrets and then use those secrets to gain elevated access to the internal database. This local, authenticated path and the requirement for session‑level access make widespread automation unlikely, but the high severity and possible data compromise remain significant risks.

Generated by OpenCVE AI on September 19, 2026 at 15:19 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM guardium_data_protection 12.2 fix from the Fix Central link that removes the hardcoded credentials from the hardware_assess/obstore binaries.
  • Replace or patch the vulnerable binaries on all affected systems to eliminate hardcoded secrets and ensure the binaries are signed and verifiable.
  • Restrict file permissions and execution rights for the hardware_assess/obstore binaries to the minimal set of privileged users and enable auditing of any accesses to these files.

Generated by OpenCVE AI on September 19, 2026 at 15:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-798
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T03:55:52.311Z

Reserved: 2026-09-01T02:06:25.475Z

Link: CVE-2026-84034

cve-icon Vulnrichment

Updated: 2026-09-19T14:04:13.435Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:26.190

Modified: 2026-10-06T16:24:42.937

Link: CVE-2026-84034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:15:06Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials