CVE-2026-8405
published 2026-05-27CVE-2026-8405: IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.23%
13.6th percentile
IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | guardium_data_protection | — | — |
| ibm | guardium_data_protection | — | — |
| ibm | guardium_data_protection | 12.2.1 – 4.4.7 Fix Pack 1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Guardium Data Protection up to 12.2.2 Debug Mode information disclosure
vuldb·2026-05-27·CVSS 6.5
CVE-2026-8405 [MEDIUM] IBM Guardium Data Protection up to 12.2.2 Debug Mode information disclosure
A vulnerability, which was classified as problematic, was found in IBM Guardium Data Protection up to 12.2.2. This impacts an unknown function of the component Debug Mode. Such manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-8405. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
GHSA
GHSA-xvcj-65f9-8jg3: IBM Guardium Data Protection 12
ghsa_unreviewed·2026-05-27
CVE-2026-8405 [MEDIUM] CWE-200 GHSA-xvcj-65f9-8jg3: IBM Guardium Data Protection 12
IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-27
Published