VYPR

Guardium Data Protection

by IBM

CVEs (61)

  • CVE-2026-82885HigSep 18, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

  • CVE-2026-81933HigSep 18, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to…

  • CVE-2026-81656HigSep 18, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data…

  • CVE-2026-81626HigSep 18, 2026
    risk 0.56cvss 8.6epss 0.00

    IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact…

  • CVE-2026-84842HigSep 29, 2026
    risk 0.53cvss 8.1epss —

    IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.

  • CVE-2026-84241HigSep 18, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

  • CVE-2026-84108HigSep 18, 2026
    risk 0.53cvss 8.1epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

  • CVE-2026-84085HigSep 18, 2026
    risk 0.53cvss 8.1epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-84081HigSep 18, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

  • CVE-2026-84077HigSep 18, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

  • CVE-2026-82892HigSep 18, 2026
    risk 0.53cvss 8.1epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-84089HigSep 18, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

  • CVE-2026-84083HigSep 18, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute…

  • CVE-2026-82893HigSep 18, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

  • CVE-2026-84105HigSep 18, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

  • CVE-2026-84440HigSep 29, 2026
    risk 0.49cvss 7.5epss —

    IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter…

  • CVE-2026-84882HigSep 25, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.

  • CVE-2026-85029HigSep 25, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-84893HigSep 25, 2026
    risk 0.49cvss 7.6epss 0.00

    IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.

  • CVE-2026-84884HigSep 25, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.