CVE-2026-84276
- EPSS -
- Veröffentlicht 08.10.2026 18:59:17
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers an u...
CVE-2026-84278
- EPSS -
- Veröffentlicht 08.10.2026 18:58:14
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper component. An authenticated high-privileged user can inject arbitrary commands through attacker-controlled arguments, resulting in ...
CVE-2026-84290
- EPSS -
- Veröffentlicht 08.10.2026 18:57:07
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM Guardium Data Protection 12.0, 12.1, 12.2 is affected by an improper validation of user-supplied pointers in the WfpMonitor kernel driver. Certain METHOD_NEITHER IOCTL handlers dereference user-controlled pointers without adequate probing and exc...
CVE-2026-84422
- EPSS 0.68%
- Veröffentlicht 29.09.2026 17:55:27
- Zuletzt bearbeitet 02.10.2026 13:46:13
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
CVE-2026-84436
- EPSS 0.68%
- Veröffentlicht 29.09.2026 17:53:14
- Zuletzt bearbeitet 02.10.2026 13:45:31
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
CVE-2026-84440
- EPSS 0.67%
- Veröffentlicht 29.09.2026 17:51:03
- Zuletzt bearbeitet 01.10.2026 15:45:56
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system com...
CVE-2026-84842
- EPSS 0.38%
- Veröffentlicht 29.09.2026 17:48:01
- Zuletzt bearbeitet 01.10.2026 15:46:25
IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service ...
CVE-2026-84862
- EPSS 0.37%
- Veröffentlicht 25.09.2026 14:03:36
- Zuletzt bearbeitet 28.09.2026 13:17:24
IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.
CVE-2026-84882
- EPSS 0.33%
- Veröffentlicht 25.09.2026 14:01:24
- Zuletzt bearbeitet 26.09.2026 04:17:48
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.
CVE-2026-84884
- EPSS 0.24%
- Veröffentlicht 25.09.2026 14:00:02
- Zuletzt bearbeitet 28.09.2026 13:17:24
IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative ...