CVE-2026-85029: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Other sources
IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
What level of access does an attacker need?
The vulnerability is remotely exploitable but requires low privileges. No user interaction is required.
What impact could successful exploitation have?
An attacker could obtain sensitive information, delete arbitrary files, or execute arbitrary code. The listed impacts include high confidentiality, integrity, and availability effects.
Which version is identified as affected?
The advisory identifies IBM Guardium Data Protection 12.2 as affected.