Ibm Guardium Data Protection — known CVE vulnerabilities
Every CVE whose affected-product data names Ibm Guardium Data Protection, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (54)
CVE-2026-84064 — CVSS 9.9 (critical): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper…
CVE-2026-84075 — CVSS 9.9 (critical): IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the…
CVE-2026-80442 — CVSS 9.9 (critical): IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate…
CVE-2026-84078 — CVSS 9.9 (critical): IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated…
CVE-2026-82340 — CVSS 9.8 (critical): IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method…
CVE-2026-84082 — CVSS 9.8 (critical): IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special…
CVE-2026-80441 — CVSS 9.8 (critical): IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery…
CVE-2026-81657 — CVSS 9.8 (critical): IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the…
CVE-2026-82967 — CVSS 9.8 (critical): IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass…
CVE-2026-82832 — CVSS 9.6 (critical): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of…
CVE-2026-84436 — CVSS 9.1 (critical): IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged…
CVE-2026-84073 — CVSS 9.1 (critical): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper…
CVE-2026-84031 — CVSS 9.0 (critical): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of…
CVE-2026-84070 — CVSS 8.9 (high): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of…
CVE-2026-84106 — CVSS 8.9 (high): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of…
CVE-2026-84074 — CVSS 8.9 (high): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of…
CVE-2026-84034 — CVSS 8.8 (high): IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A…
CVE-2026-84084 — CVSS 8.8 (high): IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF)…
CVE-2026-81656 — CVSS 8.8 (high): IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged…
CVE-2026-81933 — CVSS 8.8 (high): IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged…
CVE-2026-82885 — CVSS 8.8 (high): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in…
CVE-2026-82887 — CVSS 8.8 (high): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization…
CVE-2026-81626 — CVSS 8.6 (high): IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated…
CVE-2026-84842 — CVSS 8.1 (high): IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An…
CVE-2026-82892 — CVSS 8.1 (high): IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special…
CVE-2026-84077 — CVSS 8.1 (high): IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery…
CVE-2026-84081 — CVSS 8.1 (high): IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.
CVE-2026-84085 — CVSS 8.1 (high): IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special…
CVE-2026-84108 — CVSS 8.1 (high): IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during…
CVE-2026-84241 — CVSS 8.1 (high): IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
CVE-2026-84083 — CVSS 7.8 (high): IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector…
CVE-2026-82893 — CVSS 7.8 (high): IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.
CVE-2026-84089 — CVSS 7.8 (high): IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.
CVE-2026-84105 — CVSS 7.7 (high): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper…
CVE-2026-82896 — CVSS 7.6 (high): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal…
CVE-2026-84076 — CVSS 7.6 (high): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
CVE-2026-84239 — CVSS 7.6 (high): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper…
CVE-2026-84440 — CVSS 7.5 (high): IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated…
CVE-2026-84036 — CVSS 7.4 (high): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
CVE-2026-81669 — CVSS 7.2 (high): IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An…
CVE-2026-84086 — CVSS 7.2 (high): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a…
CVE-2026-81937 — CVSS 7.2 (high): IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A…
CVE-2026-84422 — CVSS 7.2 (high): IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality…
CVE-2026-84071 — CVSS 7.2 (high): IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A…
CVE-2025-3473 — CVSS 6.7 (medium): IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions…
CVE-2026-8405 — CVSS 6.5 (medium): IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose…
CVE-2026-81623 — CVSS 6.3 (medium): IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system…
CVE-2026-82890 — CVSS 5.9 (medium): IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper…
CVE-2025-36020 — CVSS 5.9 (medium): IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive…
CVE-2026-4918 — CVSS 5.5 (medium): IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed…
CVE-2026-1274 — CVSS 4.9 (medium): IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control…
CVE-2026-4917 — CVSS 4.9 (medium): IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a…
CVE-2026-4919 — CVSS 4.8 (medium): IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed…
CVE-2026-1272 — CVSS 2.7 (low): IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.