CVE-2026-82335: IBM Guardium Data Protection Buffer Overflow
IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser. A remote attacker could send a specially crafted MongoDB SCRAM username containing an excessive length and cause memory corruption, potentially resulting in denial of service or arbitrary code execution.
Other sources
IBM Security Guardium is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser. A remote attacker could send a specially crafted MongoDB SCRAM username containing an excessive length and cause memory corruption, potentially resulting in denial of service or arbitrary code execution.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protection Snifferto a version that resolves this vulnerability.Patch SqlGuard_12.0p4018_SnifferUpdate
Event History
Frequently Asked Questions
Which deployments are affected?
IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 are identified as vulnerable. The issue is in the MongoDB protocol parser.
What does an attacker need to exploit this issue?
A remote attacker can attempt exploitation by sending a specially crafted MongoDB SCRAM username with an excessive length. No privileges or user interaction are required, although the listed attack complexity is high.
What could successful exploitation cause?
The excessive-length username can trigger heap memory corruption. This could result in denial of service or potentially arbitrary code execution.