Description
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.
Published: 2026-09-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass in the LoadBalancerServlet enabling unauthorized privileged load‑balancer operations
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authentication check (CWE-306) in the LoadBalancerServlet of IBM Guardium Data Protection. An attacker who can reach the servlet can invoke privileged load‑balancer functions without providing credentials, which can compromise the integrity of load‑balancer configurations and impact system availability. This flaw represents a critical authentication bypass, allowing unauthenticated users to perform privileged actions.

Affected Systems

IBM Guardium Data Protection product version 12.2 is affected. No other affected versions are listed.

Risk and Exploitability

The CVSS score of 9.9 classifies this flaw as critical, indicating the potential for severe impact if exploited. While the EPSS score is not available, the lack of a public exploit listing and its absence from the CISA KEV catalog do not diminish the risk, because the flaw permits unauthenticated remote access to privileged operations. The likely attack vector is network‑based access to the vulnerable servlet endpoint, requiring no prior authentication. Given the critical severity and the ability to perform unauthorized actions, the overall risk remains high.

Generated by OpenCVE AI on September 19, 2026 at 13:56 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium Data Protection 12.2 fix pack (SqlGuard_12.0p233_FixPack) to address the missing authentication check.
  • During the remediation window, block or restrict external traffic to the load‑balancer servlet endpoints to prevent unauthenticated access.
  • After applying the fix, verify that authentication is enforced on all load‑balancer operations and document the configuration changes.

Generated by OpenCVE AI on September 19, 2026 at 13:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-306
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:36.117Z

Reserved: 2026-09-01T06:18:39.937Z

Link: CVE-2026-84078

cve-icon Vulnrichment

Updated: 2026-09-19T14:01:58.654Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:27.480

Modified: 2026-10-06T15:34:06.033

Link: CVE-2026-84078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function