CVE-2026-84272 PUBLISHED

IBM Guardium Data Protection Missing Authentication

Assigner: ibm
Reserved: 01.09.2026 Published: 08.10.2026 Updated: 08.10.2026

IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of managed edge clusters.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor IBM
Product Guardium Data Protection
Versions
  • Version 12.2.2 is affected
  • Version 12.1 is affected

Solutions

IBM encourages customers to update their systems promptly.

For all affected versions, IBM strongly recommends addressing the vulnerabilities now by applying the latest IBM Guardium Data Protection Edge patch 12.0p15004:

https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p15004_Edge&includeSupersedes=0&source=fc

For all affected versions, IBM strongly recommends addressing the vulnerabilities now by applying the latest IBM Guardium Data Protection patch 12.0p147:

https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=All&platform=All&function=fixId&fixids=SqlGuard_12.0p147_FixPack&includeSupersedes=0&source=fc

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE