Executive brief
IBM Guardium Data Protection is a database and data security monitoring platform used to protect sensitive information and enforce compliance policies. A cross-site request forgery vulnerability allows remote attackers to trick authenticated users into performing unauthorized actions, bypassing security restrictions and potentially gaining full control over the system's confidentiality, integrity, and availability.
Technical details
CVE-2026-84084 is a CSRF vulnerability (CWE-352) in IBM Guardium Data Protection 12.2 that requires user interaction (UI:R) but no prior authentication. The attack vector is network-based with low complexity, enabling an unauthenticated attacker to force a user to perform unintended state-changing actions. Exploitation could result in unauthorized bypass of security restrictions, with potential confidentiality, integrity, and availability impact.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed