Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM encourages customers to update their systems promptly. For all affected versions, IBM strongly recommends addressing the vulnerabilities now by applying the latest IBM Guardium Data Protection Edge patch 12.0p15004: https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p15004_Edge&includeSupersedes=0&source=fc For all affected versions, IBM strongly recommends addressing the vulnerabilities now by applying the latest IBM Guardium Data Protection patch 12.0p147: https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=All&platform=All&function=fixId&fixids=SqlGuard_12.0p147_FixPack&includeSupersedes=0&source=fc
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7288832 |
|
Thu, 08 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of managed edge clusters. | |
| Title | IBM Guardium Data Protection Missing Authentication | |
| First Time appeared |
Ibm
Ibm guardium Data Protection |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:ibm:guardium_data_protection:12.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:guardium_data_protection:12.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:guardium_data_protection:12.2.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm guardium Data Protection |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-10-08T19:05:27.069Z
Reserved: 2026-09-01T14:13:55.424Z
Link: CVE-2026-84272
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-306
Missing Authentication for Critical Function