CVE-2026-82885: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.
Other sources
IBM Guardium Data Protection could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be remotely authenticated. The issue is exposed through the REST API and does not require user interaction.
Which deployments are identified as affected?
IBM Guardium Data Protection 12.2 is identified as affected. The provided information does not state whether other versions or default configurations are affected.
What is the potential impact after exploitation?
A successful attacker could gain elevated privileges. The supplied severity vector indicates high impact to confidentiality, integrity, and availability.