CVE-2026-82900 PUBLISHED

IBM Guardium Data Protection is affected by multiple vulnerabilities.

Assigner: ibm
Reserved: 31.08.2026 Published: 08.10.2026 Updated: 08.10.2026

IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to delete arbitrary files due to improper limitation of a pathname to a restricted directory.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor IBM
Product Guardium Data Protection
Versions
  • Version 12.2.2 is affected
  • Version 12.1 is affected

Solutions

IBM encourages customers to update their systems promptly.

For all affected versions, IBM strongly recommends addressing the vulnerabilities now by applying the latest IBM Guardium Data Protection Edge patch 12.0p15004:

https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p15004_Edge&includeSupersedes=0&source=fc

For all affected versions, IBM strongly recommends addressing the vulnerabilities now by applying the latest IBM Guardium Data Protection patch 12.0p147:

https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=All&platform=All&function=fixId&fixids=SqlGuard_12.0p147_FixPack&includeSupersedes=0&source=fc

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE