cbcvebase.

Ibm Guardium Data Protection vulnerabilities

61 known vulnerabilities affecting ibm/guardium_data_protection.

Total CVEs
61
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH40MEDIUM8LOW1

Vulnerabilities

Page 2 of 4
CVE-2026-81626P3HIGHCVSS 8.6v12.22026-09-18
CVE-2026-81626 [HIGH] CWE-89 CVE-2026-81626: IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balance IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.
nvd
CVE-2026-84422P3HIGHCVSS 7.2v12.22026-09-29
CVE-2026-84422 [HIGH] CWE-78 CVE-2026-84422: IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME re IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
nvd
CVE-2026-81933P3HIGHCVSS 8.8v12.22026-09-18
CVE-2026-81933 [HIGH] CWE-89 CVE-2026-81933: IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Gri IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of th
nvd
CVE-2026-84034P3HIGHCVSS 8.8v12.22026-09-18
CVE-2026-84034 [HIGH] CWE-798 CVE-2026-84034: IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hard IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.
nvd
CVE-2026-84071P3HIGHCVSS 7.2v12.22026-09-18
CVE-2026-84071 [HIGH] CWE-78 CVE-2026-84071: IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector p IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.
nvd
CVE-2026-81937P3HIGHCVSS 7.2v12.22026-09-18
CVE-2026-81937 [HIGH] CWE-78 CVE-2026-81937: IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import r IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to the confidentiality, integrity, and
nvd
CVE-2026-81669P3HIGHCVSS 7.2v12.22026-09-18
CVE-2026-81669 [HIGH] CWE-78 CVE-2026-81669: IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create c IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges.
nvd
CVE-2026-84241P3HIGHCVSS 8.1v12.22026-09-18
CVE-2026-84241 [HIGH] CWE-285 CVE-2026-84241: IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
nvd
CVE-2026-84081P3HIGHCVSS 8.1v12.22026-09-18
CVE-2026-84081 [HIGH] CWE-295 CVE-2026-84081: IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.
nvd
CVE-2026-84882P3HIGHCVSS 7.5v12.22026-09-25
CVE-2026-84882 [HIGH] CWE-22 CVE-2026-84882: IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.
nvd
CVE-2026-84086P3HIGHCVSS 7.2v12.22026-09-18
CVE-2026-84086 [HIGH] CWE-22 CVE-2026-84086: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary c IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
nvd
CVE-2026-82896P3HIGHCVSS 7.6v12.22026-09-18
CVE-2026-82896 [HIGH] CWE-22 CVE-2026-82896: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directorie IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.
nvd
CVE-2026-84108P3HIGHCVSS 8.1v12.22026-09-18
CVE-2026-84108 [HIGH] CWE-79 CVE-2026-84108: IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to imp IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.
nvd
CVE-2026-84076P3HIGHCVSS 7.6v12.22026-09-18
CVE-2026-84076 [HIGH] CWE-285 CVE-2026-84076: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security res IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
nvd
CVE-2026-85029P3HIGHCVSS 7.5v12.22026-09-25
CVE-2026-85029 [HIGH] CWE-22 CVE-2026-85029: IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, del IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
nvd
CVE-2026-84842P3HIGHCVSS 8.1v12.22026-09-29
CVE-2026-84842 [HIGH] CWE-22 CVE-2026-84842: IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.
nvd
CVE-2026-84893P3HIGHCVSS 7.6v12.22026-09-25
CVE-2026-84893 [HIGH] CWE-89 CVE-2026-84893: IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticat IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.
nvd
CVE-2026-84031P3CRITICALCVSS 9.0v12.22026-09-18
CVE-2026-84031 [CRITICAL] CWE-79 CVE-2026-84031: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary c IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
nvd
CVE-2026-84070P3HIGHCVSS 8.9v12.22026-09-18
CVE-2026-84070 [HIGH] CWE-79 CVE-2026-84070: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary c IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
nvd
CVE-2026-84106P3HIGHCVSS 8.9v12.22026-09-18
CVE-2026-84106 [HIGH] CWE-79 CVE-2026-84106: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary c IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
nvd
Ibm Guardium Data Protection vulnerabilities | cvebase