Description
IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Published: 2026-09-25
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Remote code execution and data exfiltration
Action: Patch Immediately
AI Analysis

Impact

IBM Guardium Data Protection 12.2 contains a flaw in how it limits file pathnames, allowing a remote attacker to traverse to arbitrary directories. This path‑traversal weakness can lead to reading sensitive files, deleting files, or executing arbitrary code, with potential loss of confidentiality, integrity and availability. The weakness is classified as CWE‑22.

Affected Systems

The vulnerability affects IBM Guardium Data Protection 12.2, including version 12.2.0. The product runs on Linux and is mentioned in the CPE list for 12.2.*.

Risk and Exploitability

With a CVSS score of 7.5 the flaw is high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, making exploitation likelihood uncertain. The description states that a remote attacker can exploit the flaw, so the attack vector is inferred to be over the network and would require remote access to the Guardium system.

Generated by OpenCVE AI on September 25, 2026 at 17:13 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium Data Protection 12.2 fix pack from IBM’s Support site to correct the path‑traversal flaw.
  • Restart the Guardium services so the patch takes effect.
  • Limit remote access to Guardium management interfaces and enforce directory‑level permissions to reduce exposure.

Generated by OpenCVE AI on September 25, 2026 at 17:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-25T13:56:47.103Z

Reserved: 2026-09-02T20:02:31.650Z

Link: CVE-2026-85029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-25T14:17:20.050

Modified: 2026-09-25T16:08:48.610

Link: CVE-2026-85029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T17:15:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')