CVE-2026-84250: IBM Guardium Data Protection Hard-coded Credentials
IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.
Other sources
IBM Security Guardium Data Protection is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Does exploitation require local access to the affected system?
Yes. The vulnerability is described as exploitable by a local attacker; no remote attack path is identified in the available data.
Which component should be prioritized for investigation?
The issue is associated with the pkcrypto passkey component, which contains a hard-coded recovery key and weak cryptographic protection.