CVE-2026-82334
- EPSS -
- Veröffentlicht 08.10.2026 19:13:47
- Zuletzt bearbeitet 08.10.2026 20:17:36
IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol parser. A remote attacker could send a specially crafted TDS LOGIN7 packet containing invalid offset or length values, potentia...
CVE-2026-82335
- EPSS -
- Veröffentlicht 08.10.2026 19:12:31
- Zuletzt bearbeitet 08.10.2026 20:17:36
IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser. A remote attacker could send a specially crafted MongoDB SCRAM username containing an excessive length and cause memory corrup...
CVE-2026-82344
- EPSS -
- Veröffentlicht 08.10.2026 19:11:17
- Zuletzt bearbeitet 08.10.2026 20:17:37
IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reass...
CVE-2026-84244
- EPSS -
- Veröffentlicht 08.10.2026 19:08:55
- Zuletzt bearbeitet 08.10.2026 20:17:37
IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute malici...
CVE-2026-84245
- EPSS -
- Veröffentlicht 08.10.2026 19:08:20
- Zuletzt bearbeitet 08.10.2026 20:17:37
IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cp_wrapper component. A low-privileged local user could exploit this vulnerability to gain root privileges and access or modify sensitive system files.
CVE-2026-84250
- EPSS -
- Veröffentlicht 08.10.2026 19:07:44
- Zuletzt bearbeitet 08.10.2026 20:17:37
IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privile...
CVE-2026-84271
- EPSS -
- Veröffentlicht 08.10.2026 19:06:41
- Zuletzt bearbeitet 08.10.2026 20:17:37
IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer. An attacker with local access could exploit this vulnerability to execute arbitrary code with root privileges.
CVE-2026-84272
- EPSS -
- Veröffentlicht 08.10.2026 19:05:27
- Zuletzt bearbeitet 08.10.2026 20:17:37
IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of mana...
CVE-2026-84274
- EPSS -
- Veröffentlicht 08.10.2026 19:04:16
- Zuletzt bearbeitet 08.10.2026 20:17:37
IBM Guardium Data Protection 12.2.2 is affected by a sensitive information exposure vulnerability. During SECRET and API_KEY rotation processing, sensitive credential material is logged at INFO level by the edge-controller/edge-manager components. An...
CVE-2026-84275
- EPSS -
- Veröffentlicht 08.10.2026 19:03:29
- Zuletzt bearbeitet 08.10.2026 20:17:38
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.