CVE-2026-4919: IBM Guardium Data Protection is affected by multiple vulnerabilities
IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Guardium Data Protection is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4919?
CVE-2026-4919 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2026-4919?
To fix CVE-2026-4919, upgrade to the latest version of IBM Guardium Data Protection that addresses this vulnerability.
What versions of IBM Guardium Data Protection are affected by CVE-2026-4919?
CVE-2026-4919 affects IBM Guardium Data Protection version 12.1 and earlier versions.
What is cross-site scripting in the context of CVE-2026-4919?
Cross-site scripting in CVE-2026-4919 allows an attacker to inject malicious JavaScript code into the application's Web UI.
Who is primarily impacted by CVE-2026-4919?
Administrative users of IBM Guardium Data Protection are primarily impacted by CVE-2026-4919 due to the risk of unauthorized code execution.