Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
Published: 2026-09-18
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Prompt Patch
AI Analysis

Impact

IBM Guardium Data Protection version 12.2 contains an improper authorization flaw that allows a remotely authenticated attacker to bypass configured security restrictions. The vulnerability, identified as CWE‑285, could enable the attacker to perform actions beyond their intended privileges, potentially exposing sensitive data or disrupting system operations.

Affected Systems

The affected product is IBM Guardium Data Protection 12.2, including patch level 12.2.0 as referenced by the cpe strings. The release includes a fix (SqlGuard_12.0p233_FixPack) available through IBM Fix Central.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity, and the vulnerability requires authentication; the EPSS score is not available, and the vulnerability is not currently listed in CISA's KEV. Attackers must already have valid credentials but can then extend their access beyond intended limits, making prompt remediation essential.

Generated by OpenCVE AI on September 19, 2026 at 13:36 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium Data Protection 12.2 patch that addresses the authorization bypass (SqlGuard_12.0p233_FixPack).
  • Restrict privileged Guardium accounts to the minimum required roles to mitigate potential abuse.
  • Configure strict role‑based access control and monitor Guardium audit logs for abnormal activity.

Generated by OpenCVE AI on September 19, 2026 at 13:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:37.577Z

Reserved: 2026-09-01T02:08:20.389Z

Link: CVE-2026-84036

cve-icon Vulnrichment

Updated: 2026-09-19T14:03:48.750Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:26.313

Modified: 2026-10-06T16:25:00.683

Link: CVE-2026-84036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses