Executive brief
IBM Guardium Data Protection is a data security and monitoring platform used to protect sensitive databases in enterprise environments. A vulnerability in web page generation could allow an authenticated remote attacker to execute arbitrary code on the system, potentially compromising the entire monitoring infrastructure and the databases it protects. This could lead to unauthorized access to sensitive data, system compromise, or denial of service.
Technical details
CVE-2026-84106 is a code injection vulnerability resulting from improper neutralization of input during web page generation, with elements of cross-site scripting (CWE-79). The vulnerability requires remote network access and authentication, plus user interaction to exploit. A successful attack would allow an authenticated attacker to execute arbitrary code with the privileges of the Guardium service, potentially achieving full system compromise.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed