CVE-2026-4921: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Other sources
IBM Security Guardium could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Patch SqlGuard_12.0p230_GPU_Jun_2026_V12.2.3_FC
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs administrative privileges in IBM Guardium Data Protection or IBM Security Guardium. The issue is remotely reachable and does not require user interaction.
What is the impact of successful exploitation?
Detailed technical error messages returned in the browser may disclose sensitive information. The disclosed information could support further attacks against the system, but no integrity or availability impact is identified.
Which version is identified as affected?
IBM Guardium Data Protection 12.2 is identified as affected. The supplied information does not identify other affected or fixed versions.