Description
IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.
Published: 2026-09-29
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Remote file deletion and potential denial of service
Action: Immediate Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 contains a path traversal flaw in the Datasource REST component that allows an authenticated remote attacker to delete arbitrary files. This can lead to loss of critical configuration or data, potentially causing application downtime or compromising system integrity. The vulnerability specifically permits file removal beyond intended directories, enabling attackers to disrupt normal operations.

Affected Systems

The vulnerability affects IBM Guardium Data Protection version 12.2. Users running this release should verify their installed version and apply the available fix or upgrade.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, and while the EPSS score is not disclosed, the absence of a KEV listing suggests no publicly reported exploits yet. The attack vector is inferred to be remote, requiring authentication and access to the REST API. An attacker who can authenticate to the system may exploit the path traversal to remove files, causing service disruption or integrity loss.

Generated by OpenCVE AI on September 29, 2026 at 23:27 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM FixPack for Guardium Data Protection 12.2 available from IBM’s FixCentral.
  • Restrict access to the Datasource REST API by limiting traffic to trusted hosts or network segments.
  • If patching cannot be performed immediately, disable the Datasource REST component or block its ports until a fix is applied.

Generated by OpenCVE AI on September 29, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-29T21:02:00.396Z

Reserved: 2026-09-02T12:06:32.240Z

Link: CVE-2026-84842

cve-icon Vulnrichment

Updated: 2026-09-29T21:00:18.704Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:18.083

Modified: 2026-09-29T22:19:01.837

Link: CVE-2026-84842

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T00:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')