CVE-2026-84074: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Other sources
IBM Guardium Data Protection could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ibm/Information+Management/InfoSphere+Guardium (IBM Guardium Data Protection)to a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
What level of access does an attacker need?
The issue requires remote authenticated access. The provided information does not indicate what specific user role or privileges are required beyond authentication.
What is the potential impact if exploited?
A successful attacker could execute arbitrary code. The provided information does not state the execution context, affected component, or whether code execution occurs on the server or client.