Guardium Data Protection
by IBM
CVEs (57)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-84082 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | ||
| CVE-2026-84078 | Cri | 0.64 | 9.9 | 0.00 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and… | ||
| CVE-2026-84075 | Cri | 0.64 | 9.9 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet. | ||
| CVE-2026-84064 | Cri | 0.64 | 9.9 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | ||
| CVE-2026-82967 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface. | ||
| CVE-2026-82340 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and… | ||
| CVE-2026-81657 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | ||
| CVE-2026-80442 | Cri | 0.64 | 9.9 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and… | ||
| CVE-2026-80441 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application,… | ||
| CVE-2026-82832 | Cri | 0.62 | 9.6 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | ||
| CVE-2026-84073 | Cri | 0.59 | 9.1 | 0.00 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | ||
| CVE-2026-84031 | Cri | 0.59 | 9.0 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | ||
| CVE-2026-84106 | Hig | 0.58 | 8.9 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | ||
| CVE-2026-84074 | Hig | 0.58 | 8.9 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | ||
| CVE-2026-84070 | Hig | 0.58 | 8.9 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | ||
| CVE-2026-85542 | Hig | 0.57 | 8.8 | 0.02 | Sep 25, 2026 | IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary… | ||
| CVE-2026-84084 | Hig | 0.57 | 8.8 | 0.00 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability. | ||
| CVE-2026-84034 | Hig | 0.57 | 8.8 | 0.00 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal… | ||
| CVE-2026-82887 | Hig | 0.57 | 8.8 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | ||
| CVE-2026-82885 | Hig | 0.57 | 8.8 | 0.01 | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API. |
- risk 0.64cvss 9.8epss 0.01
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
- risk 0.64cvss 9.9epss 0.00
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and…
- risk 0.64cvss 9.9epss 0.01
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.
- risk 0.64cvss 9.9epss 0.01
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
- risk 0.64cvss 9.8epss 0.01
IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.
- risk 0.64cvss 9.8epss 0.01
IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and…
- risk 0.64cvss 9.8epss 0.01
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
- risk 0.64cvss 9.9epss 0.01
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and…
- risk 0.64cvss 9.8epss 0.01
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application,…
- risk 0.62cvss 9.6epss 0.01
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
- risk 0.59cvss 9.1epss 0.00
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
- risk 0.59cvss 9.0epss 0.01
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
- risk 0.58cvss 8.9epss 0.01
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
- risk 0.58cvss 8.9epss 0.01
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
- risk 0.58cvss 8.9epss 0.01
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
- risk 0.57cvss 8.8epss 0.02
IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary…
- risk 0.57cvss 8.8epss 0.00
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.
- risk 0.57cvss 8.8epss 0.00
IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal…
- risk 0.57cvss 8.8epss 0.01
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
- risk 0.57cvss 8.8epss 0.01
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.
Page 1 of 3