CVE-2026-8405: IBM Guardium Data Protection is affected by Exposure of Sensitive Information vulnerability
IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.
Other sources
IBM Guardium Data Protection's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.2.1Patch SqlGuard_12.0p1039_Security-Fix - Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.2.2Patch SqlGuard_12.0p223_Security-Fix
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8405?
CVE-2026-8405 has a medium severity rating of 6.5.
What software is affected by CVE-2026-8405?
CVE-2026-8405 affects IBM Guardium Data Protection versions 12.2.1 and 12.2.2.
How do I fix CVE-2026-8405?
To fix CVE-2026-8405, IBM recommends updating to the latest version of IBM Guardium Data Protection.
What type of vulnerability is CVE-2026-8405?
CVE-2026-8405 is classified as an Exposure of Sensitive Information vulnerability.
What could be exposed due to CVE-2026-8405?
CVE-2026-8405 could expose sensitive credentials when the Long Term Retention feature is in debug mode.