CVE-2026-4917: IBM Guardium Data Protection is affected by multiple vulnerabilities
IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
Other sources
IBM Guardium Data Protection could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4917?
CVE-2026-4917 has a high severity rating due to its ability to allow directory traversal by an administrative user.
How can I mitigate CVE-2026-4917?
To mitigate CVE-2026-4917, ensure that you apply the latest patches from IBM for Guardium Data Protection 12.1.
What systems are affected by CVE-2026-4917?
CVE-2026-4917 affects IBM Guardium Data Protection version 12.1 and earlier.
Can an attacker exploit CVE-2026-4917 remotely?
Yes, an attacker can exploit CVE-2026-4917 remotely through specially crafted URL requests.
What types of attacks does CVE-2026-4917 enable?
CVE-2026-4917 enables arbitrary file writing attacks on the system.