CVE-2026-84034: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardwareassess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.
Other sources
IBM Security Guardium is vulnerable to a hardcoded credentials vulnerability in the hardwareassess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker needs to be a low-privileged authenticated user. The issue involves recovering hardcoded product master secrets from the hardware_assess/obstore binaries.
What could an attacker do after recovering the secrets?
Recovered master secrets could enable unauthorized access to the internal database and compromise sensitive system information.