Executive brief
IBM Guardium Data Protection is a database security monitoring appliance used to protect sensitive data across enterprises. CVE-2026-84031 is a cross-site scripting vulnerability that allows an authenticated attacker to inject malicious scripts into web pages, potentially leading to session hijacking, credential theft, or unauthorized administrative actions against the system.
Technical details
This is a reflected or stored XSS vulnerability (CWE-79) in the web interface resulting from improper input neutralization during HTML generation. An authenticated user with network access can craft malicious input during a web request that executes arbitrary JavaScript in the context of another user's browser session, particularly affecting administrators due to the high CVSS scope change rating.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed