CVE-2026-82887: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Other sources
IBM Guardium Data Protection could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Does exploitation require an existing account?
Yes. The affected condition is described as requiring a remote authenticated attacker, so unauthenticated remote exploitation is not indicated by the available information.
Which deployment version is explicitly identified for prioritization?
IBM Guardium Data Protection 12.2 is explicitly identified as affected. The provided information does not identify other affected or fixed versions.
What level of access could a successful attacker obtain?
A successful attacker could execute arbitrary operating-system commands remotely. The stated impact includes high confidentiality, integrity, and availability impact.