Ibm Guardium Data Protection vulnerabilities
8 known vulnerabilities affecting ibm/guardium_data_protection.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2026-8405MEDIUMCVSS 6.5v12.2.1v12.2.2+1 more2026-05-27
CVE-2026-8405 [MEDIUM] CWE-200 CVE-2026-8405: IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named
IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.
nvd
CVE-2026-4917MEDIUMCVSS 4.9v12.12026-04-23
CVE-2026-4917 [MEDIUM] CWE-22 CVE-2026-4917: IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the
IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
nvd
CVE-2026-4919MEDIUMCVSS 4.8v12.1≥ 12.1, ≤ 26.0.0.42026-04-23
CVE-2026-4919 [MEDIUM] CWE-79 CVE-2026-4919: IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows a
IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2026-1274MEDIUMCVSS 4.9v12.0v12.1+2 more2026-04-23
CVE-2026-1274 [MEDIUM] CWE-840 CVE-2026-1274: IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerabi
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.
nvd
CVE-2026-4918MEDIUMCVSS 4.8v12.1≥ 12.1.0, ≤ 2.3.02026-04-23
CVE-2026-4918 [MEDIUM] CWE-79 CVE-2026-4918: IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability a
IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2026-1272MEDIUMCVSS 4.3v12.0v12.1+2 more2026-04-23
CVE-2026-1272 [MEDIUM] CWE-613 CVE-2026-1272: IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnera
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.
nvd
CVE-2025-36020HIGHCVSS 7.5v11.5v12.0+1 more2025-08-06
CVE-2025-36020 [HIGH] CWE-319 CVE-2025-36020: IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cl
IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.
nvd
CVE-2025-3473MEDIUMCVSS 6.7v11.5v12.12025-06-11
CVE-2025-3473 [MEDIUM] CWE-277 CVE-2025-3473: IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root
IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.
nvd