CVE-2026-84271: IBM Guardium Data Protection Signature Verification Bypass
IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer. An attacker with local access could exploit this vulnerability to execute arbitrary code with root privileges.
Other sources
IBM Security Guardium Data Protection is vulnerable to a signature verification bypass in the patch installer. An attacker with local access could exploit this vulnerability to execute arbitrary code with root privileges.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs local access to the IBM Guardium Data Protection system. Successful exploitation can result in arbitrary code execution with root privileges.
Which component is affected?
The vulnerability is in the patch installer’s signature verification process.