Description
IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.
Published: 2026-10-08
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: Root privilege escalation through hard‑coded recovery key
Action: Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 contains a hard‑coded recovery key within the pkcrypto passkey component and weak cryptographic protections. The vulnerability allows a local attacker to retrieve this key, recover the system root password, and obtain root privileges, thereby compromising the entire system’s confidentiality, integrity, and availability.

Affected Systems

The affected product is IBM Guardium Data Protection version 12.2. The fix is released as the SqlGuard_12.0p233_FixPack upgrade for 12.2.0 and later.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity. EPSS information is not available and the vulnerability is not listed under CISA KEV. Because the attack requires local access, the principal vector is local exploitation; a local attacker can leverage the hard‑coded key to elevate privileges. Based on the absence of documented public exploits, no public exploit is currently recorded, but the potential for local privilege escalation remains significant.

Generated by OpenCVE AI on October 8, 2026 at 21:06 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. ProductVersions FixIBM Guardium Data Protection12.2https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium Data Protection 12.2 fix pack (SqlGuard_12.0p233_FixPack) to eliminate the hard‑coded recovery key.
  • Review service logs for anomalous attempts to recover credential materials and investigate any suspicious activity.
  • Restrict local access to Guardium servers and enforce least privilege for console users.

Generated by OpenCVE AI on October 8, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.
Title IBM Guardium Data Protection Hard-coded Credentials
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-798
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T19:07:44.029Z

Reserved: 2026-09-01T13:20:25.340Z

Link: CVE-2026-84250

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T20:17:37.460

Modified: 2026-10-08T20:49:50.083

Link: CVE-2026-84250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:15:13Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials