CVE-2026-82892: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Other sources
IBM Guardium Data Protection could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
What access or prerequisites does an attacker need?
The available information identifies the attacker as remote. It does not state whether authentication, existing privileges, or user interaction are required.
Can affected versions or configurations be identified from the available information?
No affected versions or configuration conditions are provided. The referenced IBM support advisory is the available source for product-specific scope and remediation details.