Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
Published: 2026-09-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Patch ASAP
AI Analysis

Impact

The vulnerability permits a remote authenticated attacker to bypass security restrictions in IBM Guardium Data Protection 12.2 by exploiting an improper authorization mechanism. This flaw can allow the attacker to gain unauthorized access to protected data or perform privileged actions that the system otherwise prohibits, compromising confidentiality and the integrity of data protection controls.

Affected Systems

The affected system is IBM Guardium Data Protection version 12.2 on Linux. Users running this version of Guardium should verify their build against the fix provided at IBM’s support site.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity risk. EPSS data is not available, but the vulnerability is not listed in the CISA KEV catalog, implying no known public exploits at this time. The attack vector is remote and requires valid user credentials; the attacker must first authenticate to the system and then exploit the deficient authorization logic to elevate privileges or bypass restrictions. The absence of a public exploit does not reduce the criticality, as the flaw can be leveraged by any authenticated user who can reach the Guardium interfaces.

Generated by OpenCVE AI on September 19, 2026 at 13:32 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium Data Protection 12.2 fix pack to update the software to a patched version.
  • Review and enforce strict role‑based access controls, ensuring that users possess only the permissions required for their job functions.
  • If an immediate patch cannot be applied, isolate the Guardium servers from the public network and enable multi‑factor authentication to limit the impact of an authenticated attacker.

Generated by OpenCVE AI on September 19, 2026 at 13:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:36.400Z

Reserved: 2026-09-01T06:16:38.454Z

Link: CVE-2026-84076

cve-icon Vulnrichment

Updated: 2026-09-19T14:02:23.229Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:27.230

Modified: 2026-10-06T15:34:28.413

Link: CVE-2026-84076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses