CVE-2026-84071: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.
Other sources
IBM Security Guardium Data Protection is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Who is able to exploit this issue?
Exploitation requires a privileged, authenticated attacker who can use the Universal Connector plugin upload functionality.
What access or input is needed for exploitation?
The attacker must be able to supply a malicious filename during a Universal Connector plugin upload. The application incorporates that filename into a shell command.
What is the potential impact if exploitation succeeds?
A successful exploit may allow arbitrary operating-system command execution with root-level privileges.