CVE-2026-84275: IBM Guardium Data Protection Path Traversal
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.
Other sources
IBM Security Guardium Data Protection is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability can be exploited by an unauthenticated attacker through the GIM file-upload functionality.
Which system component is at risk?
The affected target is the Collector, where an attacker could write arbitrary files.