VYPR
Published Sep 25, 2026· Updated Sep 26, 2026· 1 source

IBM Guardium Data Protection: Seven Vulnerabilities Disclosed, Six High Severity

Key findings • Six high-severity vulnerabilities and one low-severity issue disclosed for IBM Guardium Data Protection 12.2. • Multiple vulnerabilities enable arbitrary code execution via com…

Key findings

  • Six high-severity vulnerabilities and one low-severity issue disclosed for IBM Guardium Data Protection 12.2.
  • Multiple vulnerabilities enable arbitrary code execution via command injection and insecure deserialization.
  • Path traversal and SQL injection flaws pose risks of unauthorized file writes and sensitive data access.
  • Insecure storage of REST service-account passwords could lead to credential compromise.
  • Vulnerabilities disclosed in a batch between September 23 and September 25, 2026.

On September 25, 2026, IBM disclosed seven vulnerabilities affecting Guardium Data Protection version 12.2. The batch includes six high-severity flaws and one low-severity issue, collectively impacting authentication, data integrity, and system security. The vulnerabilities were disclosed over a two-day period, with the majority appearing on September 25th.

Several of the vulnerabilities allow for arbitrary code execution. CVE-2026-85542, a command injection flaw in the GIM bundle import functionality, enables an authenticated attacker to execute arbitrary commands with elevated privileges by providing a crafted GIM bundle. Similarly, CVE-2026-84862, an insecure deserialization vulnerability in the Quartz JDBC job store, could allow an authenticated attacker to achieve arbitrary code execution. CVE-2026-85029, stemming from improper pathname limitations, also carries the risk of arbitrary code execution, alongside sensitive information disclosure and arbitrary file deletion.

Other critical vulnerabilities include CVE-2026-84882, a path traversal flaw in the Universal Connector Oracle Wallet upload component, which an authenticated attacker could exploit to write arbitrary files to the system. CVE-2026-84893, an SQL injection vulnerability in the PESI service, could allow an authenticated attacker to access sensitive information within the internal database. Additionally, CVE-2026-84884 highlights a security weakness where internal REST service-account passwords are stored in a reversible plaintext-equivalent format, potentially allowing an authenticated attacker to recover credentials and obtain administrative REST access tokens.

The single low-severity vulnerability, CVE-2026-4921, disclosed on September 23, 2026, could allow an administrative user to obtain sensitive information through detailed technical error messages returned in the browser, which could aid in further attacks.

All disclosed vulnerabilities affect IBM Guardium Data Protection version 12.2. Users are advised to consult IBM's security advisories for specific patching information and mitigation strategies. The clustered nature of these disclosures underscores the importance of timely patching and security reviews for Guardium Data Protection deployments.

The batch of vulnerabilities highlights multiple attack vectors, including command injection, SQL injection, insecure deserialization, path traversal, and insecure credential storage. The concentration of high-severity flaws in a single version indicates a significant risk for organizations running Guardium Data Protection 12.2. Prompt remediation is crucial to prevent potential data breaches and system compromise.

Key findings from this disclosure include:

  • Six high-severity vulnerabilities and one low-severity issue were disclosed for IBM Guardium Data Protection 12.2.
  • Multiple vulnerabilities allow for arbitrary code execution, including command injection and insecure deserialization.
  • Path traversal and SQL injection flaws present risks of unauthorized file writes and sensitive data access.
  • Insecure storage of REST service-account passwords could lead to credential compromise.
  • The vulnerabilities were disclosed in a batch between September 23 and September 25, 2026.

This coordinated disclosure event emphasizes the need for vigilant security practices and prompt application of patches for IBM Guardium Data Protection users.

CVEs included in this disclosure: CVE-2026-84882, CVE-2026-84862, CVE-2026-85542, CVE-2026-85029, CVE-2026-84893, CVE-2026-84884, CVE-2026-4921. For more details, refer to IBM's security advisories.

Synthesized by Vypr AI