VYPR

Guardium Data Protection

by IBM

CVEs (57)

  • CVE-2026-84082CriSep 18, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

  • CVE-2026-84078CriSep 18, 2026
    risk 0.64cvss 9.9epss 0.00

    IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and…

  • CVE-2026-84075CriSep 18, 2026
    risk 0.64cvss 9.9epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

  • CVE-2026-84064CriSep 18, 2026
    risk 0.64cvss 9.9epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

  • CVE-2026-82967CriSep 18, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

  • CVE-2026-82340CriSep 18, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and…

  • CVE-2026-81657CriSep 18, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

  • CVE-2026-80442CriSep 18, 2026
    risk 0.64cvss 9.9epss 0.01

    IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and…

  • CVE-2026-80441CriSep 18, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application,…

  • CVE-2026-82832CriSep 18, 2026
    risk 0.62cvss 9.6epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

  • CVE-2026-84073CriSep 18, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

  • CVE-2026-84031CriSep 18, 2026
    risk 0.59cvss 9.0epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

  • CVE-2026-84106HigSep 18, 2026
    risk 0.58cvss 8.9epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

  • CVE-2026-84074HigSep 18, 2026
    risk 0.58cvss 8.9epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

  • CVE-2026-84070HigSep 18, 2026
    risk 0.58cvss 8.9epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

  • CVE-2026-85542HigSep 25, 2026
    risk 0.57cvss 8.8epss 0.02

    IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary…

  • CVE-2026-84084HigSep 18, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

  • CVE-2026-84034HigSep 18, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal…

  • CVE-2026-82887HigSep 18, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-82885HigSep 18, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

Page 1 of 3