{"schema_version":1,"title":"IBM Guardium Data Protection vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 49 vulnerabilities in IBM Guardium Data Protection: 6 in the last 7 days and 48 in the last 90 days, 12 of them critical and 0 exploited in the wild. The most recent, CVE-2026-84882, was published on 25 September 2026.","url":"https://junglewise.ai/threats/technologies/guardium-data-protection","json_url":"https://junglewise.ai/threats/technologies/guardium-data-protection.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/guardium-data-protection","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":34,"all_time":49,"critical":12,"exploited":0,"last_7_days":6,"last_30_days":48,"last_90_days":48,"last_365_days":49},"latest":[{"cve":"CVE-2026-84882","cvss":7.5,"slug":"cve-2026-84882-ibm-guardium-data-protection-12-2-is-vulnerable-to-path-traversal","title":"IBM Guardium Data Protection path traversal in Oracle Wallet upload","severity":"high","exploited":false,"published_at":"2026-09-25T15:17:56.273+00:00","url":"https://junglewise.ai/threats/cve-2026-84882-ibm-guardium-data-protection-12-2-is-vulnerable-to-path-traversal"},{"cve":"CVE-2026-84862","cvss":7.2,"slug":"cve-2026-84862-ibm-guardium-data-protection-12-2-is-vulnerable-to-insecure","title":"IBM Guardium Data Protection insecure deserialization in Quartz","severity":"high","exploited":false,"published_at":"2026-09-25T15:17:56.11+00:00","url":"https://junglewise.ai/threats/cve-2026-84862-ibm-guardium-data-protection-12-2-is-vulnerable-to-insecure"},{"cve":"CVE-2026-85542","cvss":8.8,"slug":"cve-2026-85542-ibm-guardium-data-protection-12-2-is-affected-by-a-command","title":"IBM Guardium Data Protection command injection in GIM bundle import","severity":"high","exploited":false,"published_at":"2026-09-25T14:17:20.193+00:00","url":"https://junglewise.ai/threats/cve-2026-85542-ibm-guardium-data-protection-12-2-is-affected-by-a-command"},{"cve":"CVE-2026-85029","cvss":7.5,"slug":"cve-2026-85029-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker","title":"IBM Guardium Data Protection path traversal vulnerability","severity":"high","exploited":false,"published_at":"2026-09-25T14:17:20.05+00:00","url":"https://junglewise.ai/threats/cve-2026-85029-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker"},{"cve":"CVE-2026-84893","cvss":7.6,"slug":"cve-2026-84893-ibm-guardium-data-protection-12-2-is-vulnerable-to-sql-injection","title":"IBM Guardium Data Protection SQL injection in PESI service","severity":"high","exploited":false,"published_at":"2026-09-25T14:17:19.913+00:00","url":"https://junglewise.ai/threats/cve-2026-84893-ibm-guardium-data-protection-12-2-is-vulnerable-to-sql-injection"},{"cve":"CVE-2026-84884","cvss":7.5,"slug":"cve-2026-84884-ibm-guardium-data-protection-12-2-stores-internal-rest-service","title":"IBM Guardium Data Protection weak password storage in REST service account","severity":"high","exploited":false,"published_at":"2026-09-25T14:17:19.77+00:00","url":"https://junglewise.ai/threats/cve-2026-84884-ibm-guardium-data-protection-12-2-stores-internal-rest-service"},{"cve":"CVE-2026-84241","cvss":8.1,"epss":0.0047,"slug":"cve-2026-84241-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker","title":"IBM Guardium Data Protection improper authorization in REST API","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:29.013+00:00","url":"https://junglewise.ai/threats/cve-2026-84241-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker"},{"cve":"CVE-2026-84239","cvss":7.6,"epss":0.0055,"slug":"cve-2026-84239-ibm-guardium-data-protection-12-2-could-allow-a-remote","title":"IBM Guardium Data Protection SQL injection in authenticated API","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:28.887+00:00","url":"https://junglewise.ai/threats/cve-2026-84239-ibm-guardium-data-protection-12-2-could-allow-a-remote"},{"cve":"CVE-2026-84108","cvss":8.1,"epss":0.0063,"slug":"cve-2026-84108-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker","title":"IBM Guardium Data Protection code injection in web page generation","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:28.763+00:00","url":"https://junglewise.ai/threats/cve-2026-84108-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker"},{"cve":"CVE-2026-84106","cvss":8.9,"epss":0.0052,"slug":"cve-2026-84106-ibm-guardium-data-protection-12-2-could-allow-a-remote","title":"IBM Guardium Data Protection code execution via improper input neutralization","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:28.64+00:00","url":"https://junglewise.ai/threats/cve-2026-84106-ibm-guardium-data-protection-12-2-could-allow-a-remote"},{"cve":"CVE-2026-84105","cvss":7.7,"epss":0.0046,"slug":"cve-2026-84105-ibm-guardium-data-protection-12-2-could-allow-a-remote","title":"IBM Guardium Data Protection SQL injection","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:28.51+00:00","url":"https://junglewise.ai/threats/cve-2026-84105-ibm-guardium-data-protection-12-2-could-allow-a-remote"},{"cve":"CVE-2026-84089","cvss":7.8,"epss":0.0014,"slug":"cve-2026-84089-ibm-guardium-data-protection-12-2-could-allow-a-local-attacker-to","title":"IBM Guardium Data Protection privilege escalation in improper privilege management","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:28.39+00:00","url":"https://junglewise.ai/threats/cve-2026-84089-ibm-guardium-data-protection-12-2-could-allow-a-local-attacker-to"},{"cve":"CVE-2026-84086","cvss":7.2,"epss":0.0087,"slug":"cve-2026-84086-ibm-guardium-data-protection-12-2-could-allow-a-remote","title":"IBM Guardium Data Protection path traversal arbitrary code execution","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:28.27+00:00","url":"https://junglewise.ai/threats/cve-2026-84086-ibm-guardium-data-protection-12-2-could-allow-a-remote"},{"cve":"CVE-2026-84085","cvss":8.1,"epss":0.005,"slug":"cve-2026-84085-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker","title":"IBM Guardium Data Protection command injection in OS command","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:28.137+00:00","url":"https://junglewise.ai/threats/cve-2026-84085-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker"},{"cve":"CVE-2026-84084","cvss":8.8,"epss":0.0025,"slug":"cve-2026-84084-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker","title":"IBM Guardium Data Protection CSRF security bypass","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:28.01+00:00","url":"https://junglewise.ai/threats/cve-2026-84084-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker"},{"cve":"CVE-2026-84083","cvss":7.8,"epss":0.0015,"slug":"cve-2026-84083-ibm-guardium-data-protection-12-2-is-vulnerable-to-local","title":"IBM Guardium Data Protection local privilege escalation in nmap_wrapper","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:27.877+00:00","url":"https://junglewise.ai/threats/cve-2026-84083-ibm-guardium-data-protection-12-2-is-vulnerable-to-local"},{"cve":"CVE-2026-84082","cvss":9.8,"epss":0.0067,"slug":"cve-2026-84082-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker","title":"IBM Guardium Data Protection SQL injection","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:27.743+00:00","url":"https://junglewise.ai/threats/cve-2026-84082-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker"},{"cve":"CVE-2026-84081","cvss":8.1,"epss":0.0031,"slug":"cve-2026-84081-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker","title":"IBM Guardium Data Protection improper certificate validation","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:27.613+00:00","url":"https://junglewise.ai/threats/cve-2026-84081-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker"},{"cve":"CVE-2026-84078","cvss":9.9,"epss":0.0047,"slug":"cve-2026-84078-ibm-guardium-data-protection-12-2-is-vulnerable-to-a-missing","title":"IBM Guardium Data Protection missing authentication in LoadBalancerServlet","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:27.48+00:00","url":"https://junglewise.ai/threats/cve-2026-84078-ibm-guardium-data-protection-12-2-is-vulnerable-to-a-missing"},{"cve":"CVE-2026-84077","cvss":8.1,"epss":0.0026,"slug":"cve-2026-84077-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker","title":"IBM Guardium Data Protection CSRF security bypass","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:27.36+00:00","url":"https://junglewise.ai/threats/cve-2026-84077-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker"},{"cve":"CVE-2026-84076","cvss":7.6,"epss":0.0041,"slug":"cve-2026-84076-ibm-guardium-data-protection-12-2-could-allow-a-remote","title":"IBM Guardium Data Protection improper authorization bypass","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:27.23+00:00","url":"https://junglewise.ai/threats/cve-2026-84076-ibm-guardium-data-protection-12-2-could-allow-a-remote"},{"cve":"CVE-2026-84075","cvss":9.9,"epss":0.0059,"slug":"cve-2026-84075-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker","title":"IBM Guardium Data Protection authentication bypass in ChangeTrackerServlet","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:27.103+00:00","url":"https://junglewise.ai/threats/cve-2026-84075-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker"},{"cve":"CVE-2026-84074","cvss":8.9,"epss":0.0052,"slug":"cve-2026-84074-ibm-guardium-data-protection-12-2-could-allow-a-remote","title":"IBM Guardium Data Protection code execution via stored XSS","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:26.963+00:00","url":"https://junglewise.ai/threats/cve-2026-84074-ibm-guardium-data-protection-12-2-could-allow-a-remote"},{"cve":"CVE-2026-84073","cvss":9.1,"epss":0.0043,"slug":"cve-2026-84073-ibm-guardium-data-protection-12-2-could-allow-a-remote","title":"IBM Guardium Data Protection SQL injection","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:26.83+00:00","url":"https://junglewise.ai/threats/cve-2026-84073-ibm-guardium-data-protection-12-2-could-allow-a-remote"},{"cve":"CVE-2026-84071","cvss":7.2,"epss":0.0145,"slug":"cve-2026-84071-ibm-guardium-data-protection-12-2-is-vulnerable-to-os-command","title":"IBM Guardium Data Protection OS command injection in Universal Connector plugin","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:26.687+00:00","url":"https://junglewise.ai/threats/cve-2026-84071-ibm-guardium-data-protection-12-2-is-vulnerable-to-os-command"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":12,"exploited":0,"vulnerabilities":42},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"IBM AIX","slug":"aix","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/aix"},{"name":"IBM Langflow","slug":"langflow-oss","vulnerabilities":96,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"name":"IBM PowerVM VIOS","slug":"powervm-vios","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"name":"IBM i","slug":"i","vulnerabilities":69,"url":"https://junglewise.ai/threats/technologies/i"},{"name":"IBM WebSphere Application Server","slug":"websphere-application-server","vulnerabilities":62,"url":"https://junglewise.ai/threats/technologies/websphere-application-server"},{"name":"IBM Financial Transaction Manager","slug":"financial-transaction-manager","vulnerabilities":45,"url":"https://junglewise.ai/threats/technologies/financial-transaction-manager"},{"name":"IBM WebSphere Application Server Liberty","slug":"websphere-application-server-liberty","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/websphere-application-server-liberty"},{"name":"IBM Datastage On Cloud Pak For Data","slug":"datastage-on-cloud-pak-for-data","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/datastage-on-cloud-pak-for-data"},{"name":"IBM Concert","slug":"concert","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/concert"},{"name":"IBM Db2 Mirror For I","slug":"db2-mirror-for-i","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/db2-mirror-for-i"},{"name":"IBM Mq","slug":"mq","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/mq"},{"name":"IBM App Connect Enterprise","slug":"app-connect-enterprise","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/app-connect-enterprise"}],"technology":{"hub":true,"name":"IBM Guardium Data Protection","slug":"guardium-data-protection","vendor":{"name":"IBM","slug":"ibm","url":"https://junglewise.ai/threats/vendors/ibm"},"aliases":[],"category":"security-software","homepage":"https://www.ibm.com/products/guardium-data-protection","repo_url":"https://www.ibm.com/products/guardium-data-protection","description":"A data security platform that provides automated discovery, classification, and monitoring of sensitive data across hybrid cloud environments.","url":"https://junglewise.ai/threats/technologies/guardium-data-protection"},"most_severe":[{"cve":"CVE-2026-80442","cvss":9.9,"epss":0.01,"slug":"cve-2026-80442-ibm-guardium-data-protection-12-2-is-vulnerable-to-an","title":"IBM Guardium Data Protection OS command injection in exportCertificate","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:23.343+00:00","url":"https://junglewise.ai/threats/cve-2026-80442-ibm-guardium-data-protection-12-2-is-vulnerable-to-an"},{"cve":"CVE-2026-84064","cvss":9.9,"epss":0.0062,"slug":"cve-2026-84064-ibm-guardium-data-protection-12-2-could-allow-a-remote","title":"IBM Guardium Data Protection SQL injection","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:26.44+00:00","url":"https://junglewise.ai/threats/cve-2026-84064-ibm-guardium-data-protection-12-2-could-allow-a-remote"},{"cve":"CVE-2026-84075","cvss":9.9,"epss":0.0059,"slug":"cve-2026-84075-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker","title":"IBM Guardium Data Protection authentication bypass in ChangeTrackerServlet","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:27.103+00:00","url":"https://junglewise.ai/threats/cve-2026-84075-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker"},{"cve":"CVE-2026-84078","cvss":9.9,"epss":0.0047,"slug":"cve-2026-84078-ibm-guardium-data-protection-12-2-is-vulnerable-to-a-missing","title":"IBM Guardium Data Protection missing authentication in LoadBalancerServlet","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:27.48+00:00","url":"https://junglewise.ai/threats/cve-2026-84078-ibm-guardium-data-protection-12-2-is-vulnerable-to-a-missing"},{"cve":"CVE-2026-81657","cvss":9.8,"epss":0.0085,"slug":"cve-2026-81657-ibm-guardium-data-protection-12-2-could-allow-a-remote","title":"IBM Guardium Data Protection deserialization code execution","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:23.997+00:00","url":"https://junglewise.ai/threats/cve-2026-81657-ibm-guardium-data-protection-12-2-could-allow-a-remote"},{"cve":"CVE-2026-82967","cvss":9.8,"epss":0.0079,"slug":"cve-2026-82967-ibm-guardium-data-protection-12-2-is-vulnerable-to-an","title":"IBM Guardium Data Protection authentication bypass in IP-based access control","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:25.513+00:00","url":"https://junglewise.ai/threats/cve-2026-82967-ibm-guardium-data-protection-12-2-is-vulnerable-to-an"},{"cve":"CVE-2026-82340","cvss":9.8,"epss":0.007,"slug":"cve-2026-82340-ibm-guardium-data-protection-12-2-is-vulnerable-to","title":"IBM Guardium Data Protection unauthenticated deserialization in CAS listener","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:24.517+00:00","url":"https://junglewise.ai/threats/cve-2026-82340-ibm-guardium-data-protection-12-2-is-vulnerable-to"},{"cve":"CVE-2026-84082","cvss":9.8,"epss":0.0067,"slug":"cve-2026-84082-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker","title":"IBM Guardium Data Protection SQL injection","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:27.743+00:00","url":"https://junglewise.ai/threats/cve-2026-84082-ibm-guardium-data-protection-12-2-could-allow-a-remote-attacker"},{"cve":"CVE-2026-80441","cvss":9.8,"epss":0.0056,"slug":"cve-2026-80441-ibm-guardium-data-protection-12-2-is-vulnerable-to-an","title":"IBM Guardium Data Protection SQL injection in generateInsertQuery","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:23.217+00:00","url":"https://junglewise.ai/threats/cve-2026-80441-ibm-guardium-data-protection-12-2-is-vulnerable-to-an"},{"cve":"CVE-2026-82832","cvss":9.6,"epss":0.0061,"slug":"cve-2026-82832-ibm-guardium-data-protection-12-2-could-allow-a-remote","title":"IBM Guardium Data Protection code injection in web page generation","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:24.643+00:00","url":"https://junglewise.ai/threats/cve-2026-82832-ibm-guardium-data-protection-12-2-could-allow-a-remote"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}