CVE-2026-84884: IBM Guardium Data Protection vulnerability
Published Sep 17, 2026
·Updated
IBM Security Guardium Data Protection stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
Affected Software
1 affected component
IBM Guardium Data Protection<=12.2
Event History
Sep 17, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated and able to access the stored internal REST service-account credential.
2
What could an attacker do after recovering the stored password?
They could use the recovered password to obtain an administrative REST access token.