Description
IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers an unchecked type assertion, causing the edge-controller process to terminate unexpectedly.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

This vulnerability exists in IBM Guardium Data Protection 12.2.2, where an unauthenticated remote attacker can target the edge‑controller’s gRPC service. By sending malformed task data, the attacker exploits an unchecked type assertion that leads the edge‑controller process to crash. The resulting denial of service removes the availability of the protected data environment until the process is restarted or the system rebooted.

Affected Systems

Affected products are IBM Guardium Data Protection version 12.2.2, operating on Linux platforms. Version 12.2.3 contains the fix for the denial‑of‑service issue and is available through IBM’s FixCentral or product upgrade channels.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating a high severity rating. The EPSS score is not provided, and the issue is not listed in the CISA KEV catalog. Attackers only need unauthenticated network access to the privileged edge‑controller gRPC endpoint; no local privileges are required. Since the exploit can be performed remotely, it poses a significant risk of unplanned service downtime in environments that rely on Guardium for data protection.

Generated by OpenCVE AI on October 8, 2026 at 20:44 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2.3 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p15004_Edge&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Upgrade to Guardium Data Protection 12.2.3 or newer to resolve the unchecked type assertion in the edge‑controller.
  • If an immediate upgrade is infeasible, restrict inbound traffic to the gRPC port of the edge-controller, allowing only trusted hosts or network segments.
  • Monitor the edge‑controller process for unexpected crashes and enable automated restarts or high‑availability configurations.

Generated by OpenCVE AI on October 8, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers an unchecked type assertion, causing the edge-controller process to terminate unexpectedly.
Title IBM Guardium Data Protection Denial of Service
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T18:59:17.771Z

Reserved: 2026-09-01T14:17:47.236Z

Link: CVE-2026-84276

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:20:51.240

Modified: 2026-10-08T20:49:50.083

Link: CVE-2026-84276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption