No analysis available yet.
Vendor Solution
IBM encourages customers to update their systems promptly. ProductVersions FixIBM Guardium Data Protection12.2.3 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p15004_Edge&includeSupersedes=0&source=fc
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7288627 |
|
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Guardium Data Protection 12.2.2 is affected by a sensitive information exposure vulnerability. During SECRET and API_KEY rotation processing, sensitive credential material is logged at INFO level by the edge-controller/edge-manager components. An authenticated attacker with access to the relevant application or container logs could obtain these credentials and use them to impersonate services or gain unauthorized access to the Guardium control plane. | |
| Title | IBM Guardium Data Protection Information Disclosure | |
| First Time appeared |
Ibm
Ibm guardium Data Protection |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:ibm:guardium_data_protection:12.2.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm guardium Data Protection |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-10-08T19:52:26.250Z
Reserved: 2026-09-01T14:15:40.027Z
Link: CVE-2026-84274
Updated: 2026-10-08T19:52:22.526Z
Status : Awaiting Analysis
Published: 2026-10-08T20:17:37.927
Modified: 2026-10-08T20:49:50.083
Link: CVE-2026-84274
No data.
OpenCVE Enrichment
No data.
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor