Ibm

Guardium Data Protection

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 08.10.2026 19:13:47
  • Zuletzt bearbeitet 08.10.2026 20:17:36

IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol parser. A remote attacker could send a specially crafted TDS LOGIN7 packet containing invalid offset or length values, potentia...

  • EPSS -
  • Veröffentlicht 08.10.2026 19:12:31
  • Zuletzt bearbeitet 08.10.2026 20:17:36

IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser. A remote attacker could send a specially crafted MongoDB SCRAM username containing an excessive length and cause memory corrup...

  • EPSS -
  • Veröffentlicht 08.10.2026 19:11:17
  • Zuletzt bearbeitet 08.10.2026 20:17:37

IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reass...

  • EPSS -
  • Veröffentlicht 08.10.2026 19:08:55
  • Zuletzt bearbeitet 08.10.2026 20:17:37

IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute malici...

  • EPSS -
  • Veröffentlicht 08.10.2026 19:08:20
  • Zuletzt bearbeitet 08.10.2026 20:17:37

IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cp_wrapper component. A low-privileged local user could exploit this vulnerability to gain root privileges and access or modify sensitive system files.

  • EPSS -
  • Veröffentlicht 08.10.2026 19:07:44
  • Zuletzt bearbeitet 08.10.2026 20:17:37

IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privile...

  • EPSS -
  • Veröffentlicht 08.10.2026 19:06:41
  • Zuletzt bearbeitet 08.10.2026 20:17:37

IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer. An attacker with local access could exploit this vulnerability to execute arbitrary code with root privileges.

  • EPSS -
  • Veröffentlicht 08.10.2026 19:05:27
  • Zuletzt bearbeitet 08.10.2026 20:17:37

IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of mana...

  • EPSS -
  • Veröffentlicht 08.10.2026 19:04:16
  • Zuletzt bearbeitet 08.10.2026 20:17:37

IBM Guardium Data Protection 12.2.2 is affected by a sensitive information exposure vulnerability. During SECRET and API_KEY rotation processing, sensitive credential material is logged at INFO level by the edge-controller/edge-manager components. An...

  • EPSS -
  • Veröffentlicht 08.10.2026 19:03:29
  • Zuletzt bearbeitet 08.10.2026 20:17:38

IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.