VYPR

Guardium Data Protection

by IBM

CVEs (61)

  • CVE-2026-84239HigSep 18, 2026
    risk 0.49cvss 7.6epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

  • CVE-2026-84076HigSep 18, 2026
    risk 0.49cvss 7.6epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

  • CVE-2026-82896HigSep 18, 2026
    risk 0.49cvss 7.6epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

  • CVE-2026-84036HigSep 18, 2026
    risk 0.48cvss 7.4epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

  • CVE-2026-84422HigSep 29, 2026
    risk 0.47cvss 7.2epss —

    IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.

  • CVE-2026-84862HigSep 25, 2026
    risk 0.47cvss 7.2epss 0.00

    IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.

  • CVE-2026-84086HigSep 18, 2026
    risk 0.47cvss 7.2epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-84071HigSep 18, 2026
    risk 0.47cvss 7.2epss 0.01

    IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially…

  • CVE-2026-81937HigSep 18, 2026
    risk 0.47cvss 7.2epss 0.01

    IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command…

  • CVE-2026-81669HigSep 18, 2026
    risk 0.47cvss 7.2epss 0.01

    IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges.

  • CVE-2025-3473MedJun 11, 2025
    risk 0.44cvss 6.7epss 0.00

    IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.

  • CVE-2026-8405MedMay 27, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.

  • CVE-2026-81623MedSep 18, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation of user supplied input.

  • CVE-2026-82890MedSep 18, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.

  • CVE-2025-36020MedAug 6, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.

  • CVE-2026-4918MedApr 23, 2026
    risk 0.36cvss 5.5epss 0.00

    IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…

  • CVE-2026-4917MedApr 23, 2026
    risk 0.32cvss 4.9epss 0.00

    IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

  • CVE-2026-1274MedApr 23, 2026
    risk 0.32cvss 4.9epss 0.00

    IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.

  • CVE-2026-4919MedApr 23, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…

  • CVE-2026-4921LowSep 23, 2026
    risk 0.18cvss 2.7epss 0.00

    IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.