Description
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

IBM Guardium Data Protection 12.2 contains a path traversal flaw in its GIM file‑upload interface. The vulnerability allows an unauthenticated attacker to place arbitrary files on the Collector, which can lead to the execution of malicious code with Collector privileges. The weakness corresponds to CWE-22 (Path Traversal) and could be leveraged to compromise the entire Guardium deployment.

Affected Systems

Products affected are IBM Guardium Data Protection version 12.2.0 and 12.2. The specific fix is available as the SqlGuard_12.0p233 FixPack for the 12.2 release on IBM Linux and other supported platforms.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability presents a high severity risk. The exploitation does not require authentication, indicating that the attack vector is likely via the public or internal web interface that exposes the GIM file‑upload functionality. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the lack of authentication and the ability to write arbitrary files make it a compelling target for attackers.

Generated by OpenCVE AI on October 8, 2026 at 20:43 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM FixPack SqlGuard_12.0p233 for Guardium 12.2 to resolve the path traversal issue
  • If a patch cannot be applied immediately, disable or restrict access to the GIM file‑upload endpoint so that only authorized users can reach it
  • Verify that the Collector’s file system permissions restrict writable directories to trusted locations, preventing arbitrary file execution

Generated by OpenCVE AI on October 8, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.
Title IBM Guardium Data Protection Path Traversal
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T19:03:29.117Z

Reserved: 2026-09-01T14:16:52.113Z

Link: CVE-2026-84275

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T20:17:38.077

Modified: 2026-10-08T20:49:50.083

Link: CVE-2026-84275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:45:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')