CVE-2026-82334: IBM Guardium Data Protection Out-of-bounds Read
IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol parser. A remote attacker could send a specially crafted TDS LOGIN7 packet containing invalid offset or length values, potentially causing information disclosure or denial of service.
Other sources
IBM Security Guardium is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol parser. A remote attacker could send a specially crafted TDS LOGIN7 packet containing invalid offset or length values, potentially causing information disclosure or denial of service.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch Guardium_12.x.p101_r120203346_S-TAP_Windows
Event History
Frequently Asked Questions
Which IBM Guardium Data Protection versions are affected?
IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 are identified as vulnerable.
Does exploitation require authentication or user interaction?
No. The vulnerability is remotely exploitable without privileges or user interaction, although the attack complexity is rated high.
What does an attacker need to send to trigger the issue?
An attacker would need to send a specially crafted TDS LOGIN7 packet with invalid offset or length values to the TDS7 LOGIN7 protocol parser.
What impact can successful exploitation have?
Successful exploitation may cause information disclosure or denial of service. The listed severity vector rates confidentiality, integrity, and availability impact as high.