CVE-2026-81657: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Other sources
IBM Guardium Data Protection could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote, unauthenticated attacker could exploit the issue. The available information does not state any additional access requirements or network exposure conditions.
What is the potential impact of successful exploitation?
Successful exploitation could allow an attacker to execute arbitrary code on the affected system.
What vulnerability mechanism is involved?
The issue is caused by deserialization of untrusted data.