CVE-2026-4918: IBM Guardium Data Protection is affected by multiple vulnerabilities
IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Guardium Data Protection is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4918?
CVE-2026-4918 is rated as a high-severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2026-4918?
To fix CVE-2026-4918, upgrade IBM Guardium Data Protection to version 12.1 or later where the vulnerability is addressed.
What type of vulnerability is CVE-2026-4918?
CVE-2026-4918 is identified as a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-4918?
CVE-2026-4918 affects users of IBM Guardium Data Protection versions up to and including 12.1.
What can attackers achieve using CVE-2026-4918?
Attackers exploiting CVE-2026-4918 can embed arbitrary JavaScript code in the Web UI, potentially altering its intended functionality.