Executive brief
IBM Guardium Data Protection is a database security and monitoring solution used to protect sensitive data in enterprise environments. A cross-site request forgery flaw allows an attacker to trick authenticated users into performing unintended actions, potentially enabling unauthorized modifications to security policies, user accounts, or monitored database settings without the user's knowledge.
Technical details
CVE-2026-84077 is a CSRF vulnerability (CWE-352) in IBM Guardium Data Protection 12.2 that requires user interaction (victims must click a malicious link while authenticated). The attack requires network access and no special privileges. An unauthenticated attacker can cause an authenticated admin or user to unknowingly execute commands that modify system configuration or security controls. A patch is available from IBM.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed