CVE-2026-84440: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
Other sources
IBM Security Guardium is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
— IBM
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated attacker who can influence policy alert text can exploit the vulnerability. Systems using the SNMP alert notification functionality are the relevant exposure point.
What level of access could successful exploitation provide?
Attacker-controlled data can be executed as operating system commands by the SNMP alerter service. That service runs with root privileges, so command execution occurs with root-level privileges.