cbcvebase.

Ibm Guardium Data Protection vulnerabilities

61 known vulnerabilities affecting ibm/guardium_data_protection.

Total CVEs
61
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH40MEDIUM8LOW1

Vulnerabilities

Page 3 of 4
CVE-2026-84074P3HIGHCVSS 8.9v12.22026-09-18
CVE-2026-84074 [HIGH] CWE-79 CVE-2026-84074: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary c IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
nvd
CVE-2026-84083P3HIGHCVSS 7.8v12.22026-09-18
CVE-2026-84083 [HIGH] CWE-269 CVE-2026-84083: IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting in full compromise of the Collector
nvd
CVE-2026-84884P3HIGHCVSS 7.5v12.22026-09-25
CVE-2026-84884 [HIGH] CWE-256 CVE-2026-84884: IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible pla IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
nvd
CVE-2026-84862P3HIGHCVSS 7.2v12.22026-09-25
CVE-2026-84862 [HIGH] CWE-502 CVE-2026-84862: IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job s IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.
nvd
CVE-2026-84105P3HIGHCVSS 7.7v12.22026-09-18
CVE-2026-84105 [HIGH] CWE-89 CVE-2026-84105: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive in IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
nvd
CVE-2026-84036P3HIGHCVSS 7.4v12.22026-09-18
CVE-2026-84036 [HIGH] CWE-285 CVE-2026-84036: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security res IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
nvd
CVE-2026-84084P3HIGHCVSS 8.8v12.22026-09-18
CVE-2026-84084 [HIGH] CWE-352 CVE-2026-84084: IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2026-84239P3HIGHCVSS 7.6v12.22026-09-18
CVE-2026-84239 [HIGH] CWE-89 CVE-2026-84239: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive in IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
nvd
CVE-2026-84077P3HIGHCVSS 8.1v12.22026-09-18
CVE-2026-84077 [HIGH] CWE-352 CVE-2026-84077: IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.
nvd
CVE-2026-82893P3HIGHCVSS 7.8v12.22026-09-18
CVE-2026-82893 [HIGH] CWE-269 CVE-2026-82893: IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to im IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.
nvd
CVE-2026-84089P3HIGHCVSS 7.8v12.22026-09-18
CVE-2026-84089 [HIGH] CWE-269 CVE-2026-84089: IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to im IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.
nvd
CVE-2025-36020P3HIGHCVSS 7.5v11.5v12.0+1 more2025-08-06
CVE-2025-36020 [HIGH] CWE-319 CVE-2025-36020: IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cl IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.
nvd
CVE-2026-8405P3MEDIUMCVSS 6.5v12.2.1v12.2.2+1 more2026-05-27
CVE-2026-8405 [MEDIUM] CWE-200 CVE-2026-8405: IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.
nvd
CVE-2026-82890P3MEDIUMCVSS 5.9v12.22026-09-18
CVE-2026-82890 [MEDIUM] CWE-79 CVE-2026-82890: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary J IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.
nvd
CVE-2026-4917P4MEDIUMCVSS 4.9v12.12026-04-23
CVE-2026-4917 [MEDIUM] CWE-22 CVE-2026-4917: IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
nvd
CVE-2025-3473P4MEDIUMCVSS 6.7v11.5v12.12025-06-11
CVE-2025-3473 [MEDIUM] CWE-277 CVE-2025-3473: IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.
nvd
CVE-2026-1274P4MEDIUMCVSS 4.9v12.0v12.1+2 more2026-04-23
CVE-2026-1274 [MEDIUM] CWE-840 CVE-2026-1274: IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerabi IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.
nvd
CVE-2026-1272P4MEDIUMCVSS 4.3v12.0v12.1+2 more2026-04-23
CVE-2026-1272 [MEDIUM] CWE-613 CVE-2026-1272: IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnera IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.
nvd
CVE-2026-4919P4MEDIUMCVSS 4.8v12.1≥ 12.1, ≤ 26.0.0.42026-04-23
CVE-2026-4919 [MEDIUM] CWE-79 CVE-2026-4919: IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows a IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2026-4918P4MEDIUMCVSS 4.8v12.1≥ 12.1.0, ≤ 2.3.02026-04-23
CVE-2026-4918 [MEDIUM] CWE-79 CVE-2026-4918: IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability a IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
Ibm Guardium Data Protection vulnerabilities | cvebase