CVE-2026-84071
- EPSS 1.45%
- Veröffentlicht 18.09.2026 19:45:11
- Zuletzt bearbeitet 06.10.2026 16:26:47
IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by...
CVE-2026-84070
- EPSS 0.32%
- Veröffentlicht 18.09.2026 19:44:52
- Zuletzt bearbeitet 06.10.2026 16:26:35
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CVE-2026-84036
- EPSS 0.26%
- Veröffentlicht 18.09.2026 19:44:28
- Zuletzt bearbeitet 06.10.2026 16:25:00
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
CVE-2026-84064
- EPSS 0.37%
- Veröffentlicht 18.09.2026 19:43:52
- Zuletzt bearbeitet 06.10.2026 16:26:26
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
CVE-2026-84034
- EPSS 0.25%
- Veröffentlicht 18.09.2026 19:42:24
- Zuletzt bearbeitet 06.10.2026 16:24:42
IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized ...
- EPSS 0.33%
- Veröffentlicht 18.09.2026 19:34:23
- Zuletzt bearbeitet 06.10.2026 15:39:10
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CVE-2026-82967
- EPSS 0.43%
- Veröffentlicht 18.09.2026 19:33:53
- Zuletzt bearbeitet 06.10.2026 15:38:52
IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.
CVE-2026-82896
- EPSS 0.36%
- Veröffentlicht 18.09.2026 19:32:44
- Zuletzt bearbeitet 06.10.2026 15:38:45
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.
CVE-2026-82893
- EPSS 0.11%
- Veröffentlicht 18.09.2026 19:32:24
- Zuletzt bearbeitet 06.10.2026 15:38:38
IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.
CVE-2026-82892
- EPSS 0.39%
- Veröffentlicht 18.09.2026 19:32:07
- Zuletzt bearbeitet 06.10.2026 15:38:25
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.