CVE-2026-82900: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to delete arbitrary files due to improper limitation of a pathname to a restricted directory.
Other sources
IBM Guardium Data Protection could allow a remote attacker to delete arbitrary files due to improper limitation of a pathname to a restricted directory.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protection Edgeto a version that resolves this vulnerability.Patch 12.0p15004 - Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Patch 12.0p147
Event History
Frequently Asked Questions
What access would an attacker need to exploit this issue?
The issue is described as remotely exploitable, but the available information does not state whether authentication or specific privileges are required.
What could an attacker do if exploitation succeeds?
An attacker could delete arbitrary files by abusing insufficient restriction of a pathname to an intended directory.
Are default installations affected?
The available information does not specify whether the vulnerable behavior is enabled or reachable in a default configuration.