No analysis available yet.
Vendor Solution
IBM encourages customers to update their systems promptly. For all affected versions, IBM strongly recommends addressing the vulnerabilities now by applying the latest IBM Guardium Data Protection Edge patch 12.0p15004: https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p15004_Edge&includeSupersedes=0&source=fc For all affected versions, IBM strongly recommends addressing the vulnerabilities now by applying the latest IBM Guardium Data Protection patch 12.0p147: https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=All&platform=All&function=fixId&fixids=SqlGuard_12.0p147_FixPack&includeSupersedes=0&source=fc
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7288832 |
|
Thu, 08 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Title | IBM Guardium Data Protection is affected by multiple vulnerabilities. | |
| First Time appeared |
Ibm
Ibm guardium Data Protection |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:ibm:guardium_data_protection:12.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:guardium_data_protection:12.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:guardium_data_protection:12.2.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm guardium Data Protection |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-10-08T21:28:46.542Z
Reserved: 2026-09-01T05:04:35.197Z
Link: CVE-2026-84057
No data.
Status : Received
Published: 2026-10-08T22:17:33.170
Modified: 2026-10-08T22:17:33.170
Link: CVE-2026-84057
No data.
OpenCVE Enrichment
No data.
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')