CVE-2026-82967: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.
Other sources
IBM Security Guardium is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack - Upgrade
Upgrade
IBM Security Guardiumto a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote attacker can exploit it, provided they can reach the Guardium management interface over the network.
What security control is bypassed?
The vulnerability allows bypass of IP-based access controls protecting the Guardium management interface.
How can I determine whether my deployment is exposed?
Assess whether the Guardium management interface is remotely reachable and whether access to it relies on IP-based access controls. Systems meeting both conditions are relevant to this issue.