CVE-2026-84893
- EPSS 0.18%
- Veröffentlicht 25.09.2026 13:58:30
- Zuletzt bearbeitet 25.09.2026 16:08:48
IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.
CVE-2026-85029
- EPSS 0.54%
- Veröffentlicht 25.09.2026 13:56:47
- Zuletzt bearbeitet 28.09.2026 13:17:24
IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
CVE-2026-85542
- EPSS 2.41%
- Veröffentlicht 25.09.2026 13:53:50
- Zuletzt bearbeitet 27.09.2026 04:16:36
IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar co...
CVE-2026-4921
- EPSS 0.19%
- Veröffentlicht 23.09.2026 15:49:48
- Zuletzt bearbeitet 23.09.2026 19:17:30
IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
CVE-2026-84239
- EPSS 0.42%
- Veröffentlicht 18.09.2026 19:54:33
- Zuletzt bearbeitet 06.10.2026 15:32:31
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
CVE-2026-84241
- EPSS 0.3%
- Veröffentlicht 18.09.2026 19:53:26
- Zuletzt bearbeitet 06.10.2026 15:32:15
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
CVE-2026-84108
- EPSS 0.4%
- Veröffentlicht 18.09.2026 19:52:58
- Zuletzt bearbeitet 06.10.2026 15:32:38
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CVE-2026-84106
- EPSS 0.32%
- Veröffentlicht 18.09.2026 19:52:42
- Zuletzt bearbeitet 06.10.2026 15:32:47
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CVE-2026-84105
- EPSS 0.35%
- Veröffentlicht 18.09.2026 19:52:21
- Zuletzt bearbeitet 06.10.2026 15:32:55
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
CVE-2026-84089
- EPSS 0.11%
- Veröffentlicht 18.09.2026 19:52:01
- Zuletzt bearbeitet 06.10.2026 15:33:07
IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.