Search

Find a vulnerability

Search criteria

    17660 vulnerabilities by IBM

    CERTFR-2026-AVI-1256

    Vulnerability from certfr_avis - Published: 2026-10-02 - Updated: 2026-10-02

    De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    IBM QRadar Deployment Intelligence App QRadar Deployment Intelligence App versions antérieures à 3.0.20
    IBM AIX AIX version 7.2 sans les derniers correctifs de sécurité
    IBM QRadar SIEM QRadar SIEM versions 7.5.x antérieures à 7.5.0 UP16 IF01
    IBM Sterling Partner Engagement Manager Essentials Edition Sterling Partner Engagement Manager Essentials Edition versions 6.2.4.x antérieures à 6.2.4.5
    IBM QRadar Pre-Validation App QRadar Pre-Validation App versions antérieures à 3.0.0
    IBM QRadar Use Case Manager App QRadar Use Case Manager App versions antérieures à 4.2.0
    IBM QRadar SIEM QRadar SIEM versions 7.6.x antérieures à 7.6.0.4
    IBM Sterling Secure Proxy Sterling Secure Proxy versions 6.2.x antérieures à 6.2.1.3
    IBM QRadar Threat Intelligence QRadar Threat Intelligence versions antérieures à 2.6.0
    IBM Sterling Partner Engagement Manager Standard Edition Sterling Partner Engagement Manager Standard Edition versions 6.2.4.x antérieures à 6.2.4.5
    IBM Sterling Partner Engagement Manager Essentials Edition Sterling Partner Engagement Manager Essentials Edition versions 6.3.0.x antérieures à 6.3.0.3
    IBM AIX AIX version 7.3 sans les derniers correctifs de sécurité
    IBM VIOS VIOS version 4.1 sans le dernier correctif de sécurité
    IBM Sterling Secure Proxy Sterling Secure Proxy versions 6.1.x antérieures à 6.1.0.5
    References
    Bulletin de sécurité IBM 7289582 2026-09-25 vendor-advisory
    Bulletin de sécurité IBM 7289781 2026-09-28 vendor-advisory
    Bulletin de sécurité IBM 7289777 2026-09-28 vendor-advisory
    Bulletin de sécurité IBM 7290182 2026-09-30 vendor-advisory
    Bulletin de sécurité IBM 7289579 2026-09-25 vendor-advisory
    Bulletin de sécurité IBM 7289712 2026-09-28 vendor-advisory
    Bulletin de sécurité IBM 7289828 2026-09-28 vendor-advisory
    Bulletin de sécurité IBM 7289581 2026-09-25 vendor-advisory
    Bulletin de sécurité IBM 7289547 2026-09-25 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "QRadar Deployment Intelligence App versions ant\u00e9rieures \u00e0 3.0.20",
          "product": {
            "name": "QRadar Deployment Intelligence App",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "AIX version 7.2 sans les derniers correctifs de s\u00e9curit\u00e9",
          "product": {
            "name": "AIX",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "QRadar SIEM versions 7.5.x ant\u00e9rieures \u00e0 7.5.0 UP16 IF01",
          "product": {
            "name": "QRadar SIEM",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "Sterling Partner Engagement Manager Essentials Edition versions 6.2.4.x ant\u00e9rieures \u00e0 6.2.4.5",
          "product": {
            "name": "Sterling Partner Engagement Manager Essentials Edition",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "QRadar Pre-Validation App versions ant\u00e9rieures \u00e0 3.0.0",
          "product": {
            "name": "QRadar Pre-Validation App",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "QRadar Use Case Manager App versions ant\u00e9rieures \u00e0 4.2.0",
          "product": {
            "name": "QRadar Use Case Manager App",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "QRadar SIEM versions 7.6.x ant\u00e9rieures \u00e0 7.6.0.4",
          "product": {
            "name": "QRadar SIEM",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "Sterling Secure Proxy versions 6.2.x ant\u00e9rieures \u00e0 6.2.1.3",
          "product": {
            "name": "Sterling Secure Proxy",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "QRadar Threat Intelligence versions ant\u00e9rieures \u00e0 2.6.0",
          "product": {
            "name": "QRadar Threat Intelligence",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "Sterling Partner Engagement Manager Standard Edition versions 6.2.4.x ant\u00e9rieures \u00e0 6.2.4.5",
          "product": {
            "name": "Sterling Partner Engagement Manager Standard Edition",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "Sterling Partner Engagement Manager Essentials Edition versions 6.3.0.x ant\u00e9rieures \u00e0 6.3.0.3",
          "product": {
            "name": "Sterling Partner Engagement Manager Essentials Edition",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "AIX version 7.3 sans les derniers correctifs de s\u00e9curit\u00e9",
          "product": {
            "name": "AIX",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "VIOS version 4.1 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "VIOS",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "Sterling Secure Proxy versions 6.1.x ant\u00e9rieures \u00e0 6.1.0.5",
          "product": {
            "name": "Sterling Secure Proxy",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-27980",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27980"
        },
        {
          "name": "CVE-2026-58055",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58055"
        },
        {
          "name": "CVE-2026-49978",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49978"
        },
        {
          "name": "CVE-2026-5588",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5588"
        },
        {
          "name": "CVE-2026-85061",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85061"
        },
        {
          "name": "CVE-2026-59651",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59651"
        },
        {
          "name": "CVE-2026-45819",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45819"
        },
        {
          "name": "CVE-2026-44578",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44578"
        },
        {
          "name": "CVE-2026-68480",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68480"
        },
        {
          "name": "CVE-2026-82417",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82417"
        },
        {
          "name": "CVE-2026-3449",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3449"
        },
        {
          "name": "CVE-2026-59871",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59871"
        },
        {
          "name": "CVE-2026-11940",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11940"
        },
        {
          "name": "CVE-2026-68388",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68388"
        },
        {
          "name": "CVE-2026-53374",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53374"
        },
        {
          "name": "CVE-2026-42041",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42041"
        },
        {
          "name": "CVE-2026-68763",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68763"
        },
        {
          "name": "CVE-2025-39902",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-39902"
        },
        {
          "name": "CVE-2026-64268",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64268"
        },
        {
          "name": "CVE-2026-13321",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13321"
        },
        {
          "name": "CVE-2024-55565",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-55565"
        },
        {
          "name": "CVE-2026-44573",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44573"
        },
        {
          "name": "CVE-2026-16527",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16527"
        },
        {
          "name": "CVE-2026-59648",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59648"
        },
        {
          "name": "CVE-2026-69153",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-69153"
        },
        {
          "name": "CVE-2026-74581",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74581"
        },
        {
          "name": "CVE-2026-59848",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59848"
        },
        {
          "name": "CVE-2026-44580",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44580"
        },
        {
          "name": "CVE-2026-23903",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23903"
        },
        {
          "name": "CVE-2026-59645",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59645"
        },
        {
          "name": "CVE-2026-67314",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67314"
        },
        {
          "name": "CVE-2026-11721",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11721"
        },
        {
          "name": "CVE-2026-54514",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54514"
        },
        {
          "name": "CVE-2026-53399",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53399"
        },
        {
          "name": "CVE-2026-63886",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63886"
        },
        {
          "name": "CVE-2026-58013",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58013"
        },
        {
          "name": "CVE-2026-53185",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53185"
        },
        {
          "name": "CVE-2026-67214",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67214"
        },
        {
          "name": "CVE-2026-12185",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12185"
        },
        {
          "name": "CVE-2026-59874",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59874"
        },
        {
          "name": "CVE-2026-53391",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53391"
        },
        {
          "name": "CVE-2026-76172",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-76172"
        },
        {
          "name": "CVE-2026-52924",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52924"
        },
        {
          "name": "CVE-2026-77063",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77063"
        },
        {
          "name": "CVE-2026-10723",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10723"
        },
        {
          "name": "CVE-2026-63879",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63879"
        },
        {
          "name": "CVE-2026-41239",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41239"
        },
        {
          "name": "CVE-2026-41305",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41305"
        },
        {
          "name": "CVE-2026-63074",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63074"
        },
        {
          "name": "CVE-2026-68569",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68569"
        },
        {
          "name": "CVE-2025-4330",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4330"
        },
        {
          "name": "CVE-2026-65183",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65183"
        },
        {
          "name": "CVE-2026-14257",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14257"
        },
        {
          "name": "CVE-2026-73088",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73088"
        },
        {
          "name": "CVE-2026-63888",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63888"
        },
        {
          "name": "CVE-2026-2391",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2391"
        },
        {
          "name": "CVE-2026-58015",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58015"
        },
        {
          "name": "CVE-2026-84375",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84375"
        },
        {
          "name": "CVE-2026-73089",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73089"
        },
        {
          "name": "CVE-2026-53655",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53655"
        },
        {
          "name": "CVE-2026-69152",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-69152"
        },
        {
          "name": "CVE-2026-64189",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64189"
        },
        {
          "name": "CVE-2026-68525",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68525"
        },
        {
          "name": "CVE-2026-67321",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67321"
        },
        {
          "name": "CVE-2026-67313",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67313"
        },
        {
          "name": "CVE-2026-53606",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53606"
        },
        {
          "name": "CVE-2026-53397",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53397"
        },
        {
          "name": "CVE-2026-41988",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41988"
        },
        {
          "name": "CVE-2026-64276",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64276"
        },
        {
          "name": "CVE-2026-58014",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58014"
        },
        {
          "name": "CVE-2026-67315",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67315"
        },
        {
          "name": "CVE-2026-54516",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54516"
        },
        {
          "name": "CVE-2026-67320",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67320"
        },
        {
          "name": "CVE-2026-23745",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23745"
        },
        {
          "name": "CVE-2026-54515",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54515"
        },
        {
          "name": "CVE-2026-15816",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15816"
        },
        {
          "name": "CVE-2026-53550",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53550"
        },
        {
          "name": "CVE-2025-59471",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-59471"
        },
        {
          "name": "CVE-2026-16221",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16221"
        },
        {
          "name": "CVE-2026-63913",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63913"
        },
        {
          "name": "CVE-2026-65911",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65911"
        },
        {
          "name": "CVE-2026-18401",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18401"
        },
        {
          "name": "CVE-2026-44494",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44494"
        },
        {
          "name": "CVE-2026-9323",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9323"
        },
        {
          "name": "CVE-2025-15284",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15284"
        },
        {
          "name": "CVE-2026-12860",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12860"
        },
        {
          "name": "CVE-2026-63073",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63073"
        },
        {
          "name": "CVE-2026-65901",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65901"
        },
        {
          "name": "CVE-2026-42036",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42036"
        },
        {
          "name": "CVE-2026-42536",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42536"
        },
        {
          "name": "CVE-2026-59652",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59652"
        },
        {
          "name": "CVE-2026-61487",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-61487"
        },
        {
          "name": "CVE-2026-65903",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65903"
        },
        {
          "name": "CVE-2024-56602",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-56602"
        },
        {
          "name": "CVE-2026-65900",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65900"
        },
        {
          "name": "CVE-2026-59844",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59844"
        },
        {
          "name": "CVE-2026-66010",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66010"
        },
        {
          "name": "CVE-2026-75604",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75604"
        },
        {
          "name": "CVE-2026-44572",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44572"
        },
        {
          "name": "CVE-2026-43871",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43871"
        },
        {
          "name": "CVE-2026-44690",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44690"
        },
        {
          "name": "CVE-2026-63800",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63800"
        },
        {
          "name": "CVE-2021-23337",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-23337"
        },
        {
          "name": "CVE-2026-5758",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5758"
        },
        {
          "name": "CVE-2026-59949",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59949"
        },
        {
          "name": "CVE-2026-58012",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58012"
        },
        {
          "name": "CVE-2026-34043",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34043"
        },
        {
          "name": "CVE-2026-59880",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59880"
        },
        {
          "name": "CVE-2026-11822",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11822"
        },
        {
          "name": "CVE-2026-82333",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82333"
        },
        {
          "name": "CVE-2025-64718",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64718"
        },
        {
          "name": "CVE-2026-43951",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43951"
        },
        {
          "name": "CVE-2025-62718",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-62718"
        },
        {
          "name": "CVE-2026-44990",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44990"
        },
        {
          "name": "CVE-2026-49458",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49458"
        },
        {
          "name": "CVE-2026-4800",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4800"
        },
        {
          "name": "CVE-2026-65914",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65914"
        },
        {
          "name": "CVE-2026-44631",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44631"
        },
        {
          "name": "CVE-2026-65913",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65913"
        },
        {
          "name": "CVE-2026-59647",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59647"
        },
        {
          "name": "CVE-2026-73086",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73086"
        },
        {
          "name": "CVE-2026-58059",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58059"
        },
        {
          "name": "CVE-2026-0540",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0540"
        },
        {
          "name": "CVE-2026-8763",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8763"
        },
        {
          "name": "CVE-2026-48988",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48988"
        },
        {
          "name": "CVE-2026-41989",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41989"
        },
        {
          "name": "CVE-2026-48913",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48913"
        },
        {
          "name": "CVE-2026-49268",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49268"
        },
        {
          "name": "CVE-2026-33671",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33671"
        },
        {
          "name": "CVE-2026-5598",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5598"
        },
        {
          "name": "CVE-2026-65182",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65182"
        },
        {
          "name": "CVE-2026-42033",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42033"
        },
        {
          "name": "CVE-2026-65912",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65912"
        },
        {
          "name": "CVE-2026-42035",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42035"
        },
        {
          "name": "CVE-2026-58472",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58472"
        },
        {
          "name": "CVE-2026-56130",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56130"
        },
        {
          "name": "CVE-2026-18446",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18446"
        },
        {
          "name": "CVE-2026-44495",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44495"
        },
        {
          "name": "CVE-2026-73633",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73633"
        },
        {
          "name": "CVE-2026-15588",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15588"
        },
        {
          "name": "CVE-2026-59850",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59850"
        },
        {
          "name": "CVE-2026-84292",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84292"
        },
        {
          "name": "CVE-2026-64647",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64647"
        },
        {
          "name": "CVE-2026-64648",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64648"
        },
        {
          "name": "CVE-2026-46120",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46120"
        },
        {
          "name": "CVE-2026-49975",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49975"
        },
        {
          "name": "CVE-2026-53329",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53329"
        },
        {
          "name": "CVE-2026-33750",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33750"
        },
        {
          "name": "CVE-2026-5038",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5038"
        },
        {
          "name": "CVE-2026-34478",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34478"
        },
        {
          "name": "CVE-2024-57849",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-57849"
        },
        {
          "name": "CVE-2026-18525",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18525"
        },
        {
          "name": "CVE-2026-2359",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2359"
        },
        {
          "name": "CVE-2026-42043",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42043"
        },
        {
          "name": "CVE-2026-15055",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15055"
        },
        {
          "name": "CVE-2026-64320",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64320"
        },
        {
          "name": "CVE-2026-45822",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45822"
        },
        {
          "name": "CVE-2026-34480",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34480"
        },
        {
          "name": "CVE-2026-14682",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14682"
        },
        {
          "name": "CVE-2026-44186",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44186"
        },
        {
          "name": "CVE-2026-73180",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73180"
        },
        {
          "name": "CVE-2022-24999",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-24999"
        },
        {
          "name": "CVE-2026-59869",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59869"
        },
        {
          "name": "CVE-2026-58010",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58010"
        },
        {
          "name": "CVE-2025-7783",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-7783"
        },
        {
          "name": "CVE-2025-27152",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-27152"
        },
        {
          "name": "CVE-2026-65904",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65904"
        },
        {
          "name": "CVE-2026-58061",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58061"
        },
        {
          "name": "CVE-2026-40175",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40175"
        },
        {
          "name": "CVE-2026-53009",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53009"
        },
        {
          "name": "CVE-2026-49459",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49459"
        },
        {
          "name": "CVE-2026-63884",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63884"
        },
        {
          "name": "CVE-2026-5079",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5079"
        },
        {
          "name": "CVE-2026-64048",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64048"
        },
        {
          "name": "CVE-2025-68161",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68161"
        },
        {
          "name": "CVE-2026-84371",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84371"
        },
        {
          "name": "CVE-2026-41240",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41240"
        },
        {
          "name": "CVE-2026-67317",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67317"
        },
        {
          "name": "CVE-2026-34479",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34479"
        },
        {
          "name": "CVE-2026-59887",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59887"
        },
        {
          "name": "CVE-2026-43828",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43828"
        },
        {
          "name": "CVE-2026-26960",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-26960"
        },
        {
          "name": "CVE-2026-42040",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42040"
        },
        {
          "name": "CVE-2026-53392",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53392"
        },
        {
          "name": "CVE-2026-64018",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64018"
        },
        {
          "name": "CVE-2026-4867",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4867"
        },
        {
          "name": "CVE-2025-71132",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-71132"
        },
        {
          "name": "CVE-2026-11824",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11824"
        },
        {
          "name": "CVE-2026-64191",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64191"
        },
        {
          "name": "CVE-2026-27903",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27903"
        },
        {
          "name": "CVE-2026-58060",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58060"
        },
        {
          "name": "CVE-2026-59875",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59875"
        },
        {
          "name": "CVE-2026-12802",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12802"
        },
        {
          "name": "CVE-2026-34356",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34356"
        },
        {
          "name": "CVE-2026-44581",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44581"
        },
        {
          "name": "CVE-2026-42535",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42535"
        },
        {
          "name": "CVE-2026-54512",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54512"
        },
        {
          "name": "CVE-2026-53189",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53189"
        },
        {
          "name": "CVE-2026-58063",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58063"
        },
        {
          "name": "CVE-2026-29057",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-29057"
        },
        {
          "name": "CVE-2022-3517",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-3517"
        },
        {
          "name": "CVE-2026-65899",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65899"
        },
        {
          "name": "CVE-2026-67319",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67319"
        },
        {
          "name": "CVE-2026-44577",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44577"
        },
        {
          "name": "CVE-2026-59873",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59873"
        },
        {
          "name": "CVE-2026-70907",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-70907"
        },
        {
          "name": "CVE-2026-59646",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59646"
        },
        {
          "name": "CVE-2026-24842",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24842"
        },
        {
          "name": "CVE-2026-45991",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45991"
        },
        {
          "name": "CVE-2026-58011",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58011"
        },
        {
          "name": "CVE-2026-34355",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34355"
        },
        {
          "name": "CVE-2026-23950",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23950"
        },
        {
          "name": "CVE-2026-2327",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2327"
        },
        {
          "name": "CVE-2026-2950",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2950"
        },
        {
          "name": "CVE-2026-3304",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3304"
        },
        {
          "name": "CVE-2026-64641",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64641"
        },
        {
          "name": "CVE-2026-40895",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40895"
        },
        {
          "name": "CVE-2026-63076",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63076"
        },
        {
          "name": "CVE-2025-59250",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-59250"
        },
        {
          "name": "CVE-2026-64645",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64645"
        },
        {
          "name": "CVE-2026-12816",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12816"
        },
        {
          "name": "CVE-2026-59878",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59878"
        },
        {
          "name": "CVE-2026-59888",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59888"
        },
        {
          "name": "CVE-2026-13149",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13149"
        },
        {
          "name": "CVE-2026-29170",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-29170"
        },
        {
          "name": "CVE-2025-69873",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-69873"
        },
        {
          "name": "CVE-2026-45970",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45970"
        },
        {
          "name": "CVE-2026-63887",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63887"
        },
        {
          "name": "CVE-2026-16440",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16440"
        },
        {
          "name": "CVE-2026-64496",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64496"
        },
        {
          "name": "CVE-2026-66422",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66422"
        },
        {
          "name": "CVE-2025-68458",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68458"
        },
        {
          "name": "CVE-2026-16529",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16529"
        },
        {
          "name": "CVE-2026-55995",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55995"
        },
        {
          "name": "CVE-2026-3520",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3520"
        },
        {
          "name": "CVE-2026-44582",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44582"
        },
        {
          "name": "CVE-2026-29786",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-29786"
        },
        {
          "name": "CVE-2025-54518",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-54518"
        },
        {
          "name": "CVE-2026-15603",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15603"
        },
        {
          "name": "CVE-2026-44487",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44487"
        },
        {
          "name": "CVE-2026-13506",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13506"
        },
        {
          "name": "CVE-2026-75899",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75899"
        },
        {
          "name": "CVE-2026-42038",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42038"
        },
        {
          "name": "CVE-2026-49844",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49844"
        },
        {
          "name": "CVE-2020-15366",
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-15366"
        },
        {
          "name": "CVE-2026-42039",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42039"
        },
        {
          "name": "CVE-2026-59879",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59879"
        },
        {
          "name": "CVE-2026-58471",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58471"
        },
        {
          "name": "CVE-2026-9358",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9358"
        },
        {
          "name": "CVE-2026-43206",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43206"
        },
        {
          "name": "CVE-2026-73634",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73634"
        },
        {
          "name": "CVE-2026-59846",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59846"
        },
        {
          "name": "CVE-2026-33672",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33672"
        },
        {
          "name": "CVE-2026-8723",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8723"
        },
        {
          "name": "CVE-2026-75838",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75838"
        },
        {
          "name": "CVE-2026-64219",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64219"
        },
        {
          "name": "CVE-2026-64277",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64277"
        },
        {
          "name": "CVE-2026-53136",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53136"
        },
        {
          "name": "CVE-2026-11979",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11979"
        },
        {
          "name": "CVE-2026-54517",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54517"
        },
        {
          "name": "CVE-2026-25639",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25639"
        },
        {
          "name": "CVE-2026-42044",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42044"
        },
        {
          "name": "CVE-2026-65905",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65905"
        },
        {
          "name": "CVE-2026-53016",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53016"
        },
        {
          "name": "CVE-2018-16487",
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-16487"
        },
        {
          "name": "CVE-2026-63670",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63670"
        },
        {
          "name": "CVE-2026-77078",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77078"
        },
        {
          "name": "CVE-2026-59642",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59642"
        },
        {
          "name": "CVE-2026-75803",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75803"
        },
        {
          "name": "CVE-2026-17523",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-17523"
        },
        {
          "name": "CVE-2026-64646",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64646"
        },
        {
          "name": "CVE-2026-42034",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42034"
        },
        {
          "name": "CVE-2026-73635",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73635"
        },
        {
          "name": "CVE-2026-61308",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-61308"
        },
        {
          "name": "CVE-2025-5889",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5889"
        },
        {
          "name": "CVE-2026-75931",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75931"
        },
        {
          "name": "CVE-2026-44576",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44576"
        },
        {
          "name": "CVE-2026-54411",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54411"
        },
        {
          "name": "CVE-2026-54513",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54513"
        },
        {
          "name": "CVE-2025-46653",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-46653"
        },
        {
          "name": "CVE-2025-71176",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-71176"
        },
        {
          "name": "CVE-2026-65927",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65927"
        },
        {
          "name": "CVE-2025-68157",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68157"
        },
        {
          "name": "CVE-2026-59638",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59638"
        },
        {
          "name": "CVE-2026-54518",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54518"
        },
        {
          "name": "CVE-2025-27789",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-27789"
        },
        {
          "name": "CVE-2026-13676",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13676"
        },
        {
          "name": "CVE-2026-60589",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-60589"
        },
        {
          "name": "CVE-2026-67312",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67312"
        },
        {
          "name": "CVE-2026-6322",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6322"
        },
        {
          "name": "CVE-2026-45623",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45623"
        },
        {
          "name": "CVE-2026-5078",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5078"
        },
        {
          "name": "CVE-2026-58062",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58062"
        },
        {
          "name": "CVE-2026-12143",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12143"
        },
        {
          "name": "CVE-2026-67318",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67318"
        },
        {
          "name": "CVE-2026-26996",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-26996"
        },
        {
          "name": "CVE-2026-44486",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44486"
        },
        {
          "name": "CVE-2026-44119",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44119"
        },
        {
          "name": "CVE-2026-13204",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13204"
        },
        {
          "name": "CVE-2026-64643",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64643"
        },
        {
          "name": "CVE-2026-49356",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49356"
        },
        {
          "name": "CVE-2026-42264",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42264"
        },
        {
          "name": "CVE-2026-12803",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12803"
        },
        {
          "name": "CVE-2026-59650",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59650"
        },
        {
          "name": "CVE-2025-64756",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64756"
        },
        {
          "name": "CVE-2026-44496",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44496"
        },
        {
          "name": "CVE-2026-0636",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0636"
        },
        {
          "name": "CVE-2026-44492",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44492"
        },
        {
          "name": "CVE-2026-39865",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39865"
        },
        {
          "name": "CVE-2026-41238",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41238"
        },
        {
          "name": "CVE-2026-48586",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48586"
        },
        {
          "name": "CVE-2026-52991",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-52991"
        },
        {
          "name": "CVE-2026-59847",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59847"
        },
        {
          "name": "CVE-2026-16526",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16526"
        },
        {
          "name": "CVE-2026-11622",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11622"
        },
        {
          "name": "CVE-2026-42037",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42037"
        },
        {
          "name": "CVE-2026-64379",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64379"
        },
        {
          "name": "CVE-2026-42042",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42042"
        },
        {
          "name": "CVE-2026-54874",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54874"
        },
        {
          "name": "CVE-2026-67213",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67213"
        },
        {
          "name": "CVE-2026-13586",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13586"
        },
        {
          "name": "CVE-2026-64649",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64649"
        },
        {
          "name": "CVE-2026-16524",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16524"
        },
        {
          "name": "CVE-2026-73566",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73566"
        },
        {
          "name": "CVE-2025-58754",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-58754"
        },
        {
          "name": "CVE-2026-12590",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12590"
        },
        {
          "name": "CVE-2026-34477",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34477"
        },
        {
          "name": "CVE-2026-65902",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65902"
        },
        {
          "name": "CVE-2026-75975",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75975"
        },
        {
          "name": "CVE-2026-6321",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6321"
        },
        {
          "name": "CVE-2026-48801",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48801"
        },
        {
          "name": "CVE-2026-44490",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44490"
        },
        {
          "name": "CVE-2026-69192",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-69192"
        },
        {
          "name": "CVE-2026-59639",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59639"
        },
        {
          "name": "CVE-2026-58469",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58469"
        },
        {
          "name": "CVE-2026-16313",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16313"
        },
        {
          "name": "CVE-2026-54371",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54371"
        },
        {
          "name": "CVE-2026-68494",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68494"
        },
        {
          "name": "CVE-2026-44185",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44185"
        },
        {
          "name": "CVE-2026-29063",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-29063"
        },
        {
          "name": "CVE-2026-64298",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64298"
        },
        {
          "name": "CVE-2026-70906",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-70906"
        },
        {
          "name": "CVE-2026-23901",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23901"
        },
        {
          "name": "CVE-2026-59845",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59845"
        },
        {
          "name": "CVE-2026-67316",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67316"
        },
        {
          "name": "CVE-2025-14813",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14813"
        },
        {
          "name": "CVE-2026-31802",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31802"
        },
        {
          "name": "CVE-2025-13465",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13465"
        },
        {
          "name": "CVE-2026-29167",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-29167"
        },
        {
          "name": "CVE-2026-41907",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41907"
        },
        {
          "name": "CVE-2026-44488",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44488"
        },
        {
          "name": "CVE-2026-59843",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59843"
        },
        {
          "name": "CVE-2026-34481",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34481"
        },
        {
          "name": "CVE-2026-27904",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27904"
        },
        {
          "name": "CVE-2026-8286",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8286"
        },
        {
          "name": "CVE-2026-10805",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10805"
        },
        {
          "name": "CVE-2026-42338",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42338"
        },
        {
          "name": "CVE-2026-83557",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-83557"
        },
        {
          "name": "CVE-2026-63072",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63072"
        },
        {
          "name": "CVE-2026-77310",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77310"
        },
        {
          "name": "CVE-2026-65898",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65898"
        },
        {
          "name": "CVE-2026-73646",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73646"
        },
        {
          "name": "CVE-2026-59889",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59889"
        }
      ],
      "initial_release_date": "2026-10-02T00:00:00",
      "last_revision_date": "2026-10-02T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1256",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-10-02T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Injection de code indirecte \u00e0 distance (XSS)"
        },
        {
          "description": "Injection de requ\u00eates ill\u00e9gitimes par rebond (CSRF)"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
      "vendor_advisories": [
        {
          "published_at": "2026-09-25",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289582",
          "url": "https://www.ibm.com/support/pages/node/7289582"
        },
        {
          "published_at": "2026-09-28",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289781",
          "url": "https://www.ibm.com/support/pages/node/7289781"
        },
        {
          "published_at": "2026-09-28",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289777",
          "url": "https://www.ibm.com/support/pages/node/7289777"
        },
        {
          "published_at": "2026-09-30",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7290182",
          "url": "https://www.ibm.com/support/pages/node/7290182"
        },
        {
          "published_at": "2026-09-25",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289579",
          "url": "https://www.ibm.com/support/pages/node/7289579"
        },
        {
          "published_at": "2026-09-28",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289712",
          "url": "https://www.ibm.com/support/pages/node/7289712"
        },
        {
          "published_at": "2026-09-28",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289828",
          "url": "https://www.ibm.com/support/pages/node/7289828"
        },
        {
          "published_at": "2026-09-25",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289581",
          "url": "https://www.ibm.com/support/pages/node/7289581"
        },
        {
          "published_at": "2026-09-25",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289547",
          "url": "https://www.ibm.com/support/pages/node/7289547"
        }
      ]
    }

    CERTFR-2026-AVI-1233

    Vulnerability from certfr_avis - Published: 2026-09-25 - Updated: 2026-09-25

    De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    IBM Sterling Sterling Secure Proxy versions 6.1.x antérieures à 6.1.0.5
    IBM WebSphere Hybrid Edition WebSphere Hybrid Edition version 5.1 sans le correctif pour APAR DT497707
    IBM WebSphere Application Server WebSphere Application Server Liberty sans le correctif pour APAR DT497707
    IBM Sterling Sterling Secure Proxy versions 6.2.x antérieures à 6.2.1.3
    IBM QRadar QRadar AI Assistant versions antérieures à 2.3.0
    IBM Sterling Control Center Sterling Control Center versions 6.3.x antérieures à 6.3.1.0 iFix11
    IBM AIX AIX versions 7.3 sans le correctif 7168mb.260916.epkg.Z
    IBM QRadar QRadar Log Source Management App versions antérieures à 7.0.18
    IBM Db2 Db2 Genius Hub & Agentics versions antérieures à 1.1.5
    IBM QRadar Security QRadar Log Management AQL Plugin versions antérieures à 1.1.9
    IBM QRadar QRadar App SDK versions antérieures à 2.2.7
    IBM Sterling Control Center Sterling Control Center versions 6.4.x antérieures à 6.4.2.0 iFix07
    References
    Bulletin de sécurité IBM 7289042 2026-09-23 vendor-advisory
    Bulletin de sécurité IBM 7288723 2026-09-21 vendor-advisory
    Bulletin de sécurité IBM 7288869 2026-09-22 vendor-advisory
    Bulletin de sécurité IBM 7288863 2026-09-22 vendor-advisory
    Bulletin de sécurité IBM 7288871 2026-09-22 vendor-advisory
    Bulletin de sécurité IBM 7288868 2026-09-22 vendor-advisory
    Bulletin de sécurité IBM 7289047 2026-09-23 vendor-advisory
    Bulletin de sécurité IBM 7288650 2026-09-21 vendor-advisory
    Bulletin de sécurité IBM 7289363 2026-09-24 vendor-advisory
    Bulletin de sécurité IBM 7289341 2026-09-24 vendor-advisory
    Bulletin de sécurité IBM 7288632 2026-09-21 vendor-advisory
    Bulletin de sécurité IBM 7289320 2026-09-24 vendor-advisory
    Bulletin de sécurité IBM 7288873 2026-09-22 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Sterling Secure Proxy versions 6.1.x ant\u00e9rieures \u00e0 6.1.0.5",
          "product": {
            "name": "Sterling",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "WebSphere Hybrid Edition version 5.1 sans le correctif pour APAR DT497707",
          "product": {
            "name": "WebSphere Hybrid Edition",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "WebSphere Application Server Liberty sans le correctif pour APAR DT497707",
          "product": {
            "name": "WebSphere Application Server",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "Sterling Secure Proxy versions 6.2.x ant\u00e9rieures \u00e0 6.2.1.3",
          "product": {
            "name": "Sterling",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "QRadar AI Assistant versions ant\u00e9rieures \u00e0 2.3.0",
          "product": {
            "name": "QRadar",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "Sterling Control Center versions 6.3.x ant\u00e9rieures \u00e0 6.3.1.0 iFix11",
          "product": {
            "name": "Sterling Control Center",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "AIX versions 7.3 sans le correctif 7168mb.260916.epkg.Z",
          "product": {
            "name": "AIX",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "QRadar Log Source Management App versions ant\u00e9rieures \u00e0 7.0.18",
          "product": {
            "name": "QRadar",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "Db2 Genius Hub \u0026 Agentics versions ant\u00e9rieures \u00e0 1.1.5",
          "product": {
            "name": "Db2",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "Security QRadar Log Management AQL Plugin versions ant\u00e9rieures \u00e0 1.1.9",
          "product": {
            "name": "QRadar",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "QRadar App SDK versions ant\u00e9rieures \u00e0 2.2.7",
          "product": {
            "name": "QRadar",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        },
        {
          "description": "Sterling Control Center versions 6.4.x ant\u00e9rieures \u00e0 6.4.2.0 iFix07",
          "product": {
            "name": "Sterling Control Center",
            "vendor": {
              "name": "IBM",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2021-44906",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-44906"
        },
        {
          "name": "CVE-2026-59651",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59651"
        },
        {
          "name": "CVE-2026-6402",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6402"
        },
        {
          "name": "CVE-2026-45819",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45819"
        },
        {
          "name": "CVE-2026-13697",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13697"
        },
        {
          "name": "CVE-2026-82417",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82417"
        },
        {
          "name": "CVE-2026-3449",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3449"
        },
        {
          "name": "CVE-2018-14042",
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-14042"
        },
        {
          "name": "CVE-2026-41254",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41254"
        },
        {
          "name": "CVE-2024-29041",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-29041"
        },
        {
          "name": "CVE-2025-12816",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12816"
        },
        {
          "name": "CVE-2026-63384",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63384"
        },
        {
          "name": "CVE-2026-33895",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33895"
        },
        {
          "name": "CVE-2022-46175",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-46175"
        },
        {
          "name": "CVE-2025-27516",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-27516"
        },
        {
          "name": "CVE-2026-9595",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9595"
        },
        {
          "name": "CVE-2026-53666",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53666"
        },
        {
          "name": "CVE-2026-59648",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59648"
        },
        {
          "name": "CVE-2026-69153",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-69153"
        },
        {
          "name": "CVE-2026-85014",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85014"
        },
        {
          "name": "CVE-2024-4068",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-4068"
        },
        {
          "name": "CVE-2022-2596",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-2596"
        },
        {
          "name": "CVE-2026-71290",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-71290"
        },
        {
          "name": "CVE-2026-59645",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59645"
        },
        {
          "name": "CVE-2026-14643",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14643"
        },
        {
          "name": "CVE-2023-26158",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-26158"
        },
        {
          "name": "CVE-2018-14040",
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-14040"
        },
        {
          "name": "CVE-2026-25793",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25793"
        },
        {
          "name": "CVE-2026-53668",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53668"
        },
        {
          "name": "CVE-2026-16243",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16243"
        },
        {
          "name": "CVE-2024-43799",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-43799"
        },
        {
          "name": "CVE-2026-67214",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67214"
        },
        {
          "name": "CVE-2026-12185",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12185"
        },
        {
          "name": "CVE-2026-47010",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47010"
        },
        {
          "name": "CVE-2026-69249",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-69249"
        },
        {
          "name": "CVE-2026-76172",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-76172"
        },
        {
          "name": "CVE-2026-1527",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1527"
        },
        {
          "name": "CVE-2026-85008",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85008"
        },
        {
          "name": "CVE-2026-13505",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13505"
        },
        {
          "name": "CVE-2026-41305",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41305"
        },
        {
          "name": "CVE-2026-22701",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22701"
        },
        {
          "name": "CVE-2024-56326",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-56326"
        },
        {
          "name": "CVE-2026-14257",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14257"
        },
        {
          "name": "CVE-2026-16729",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16729"
        },
        {
          "name": "CVE-2026-6429",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6429"
        },
        {
          "name": "CVE-2026-73088",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73088"
        },
        {
          "name": "CVE-2026-75509",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75509"
        },
        {
          "name": "CVE-2026-2391",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2391"
        },
        {
          "name": "CVE-2026-84375",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84375"
        },
        {
          "name": "CVE-2026-73089",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73089"
        },
        {
          "name": "CVE-2026-47057",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47057"
        },
        {
          "name": "CVE-2022-25883",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-25883"
        },
        {
          "name": "CVE-2026-69152",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-69152"
        },
        {
          "name": "CVE-2023-44270",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-44270"
        },
        {
          "name": "CVE-2026-53550",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53550"
        },
        {
          "name": "CVE-2018-1313",
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1313"
        },
        {
          "name": "CVE-2026-16221",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16221"
        },
        {
          "name": "CVE-2022-46337",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-46337"
        },
        {
          "name": "CVE-2023-45133",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45133"
        },
        {
          "name": "CVE-2026-12860",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12860"
        },
        {
          "name": "CVE-2026-59652",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59652"
        },
        {
          "name": "CVE-2026-61487",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-61487"
        },
        {
          "name": "CVE-2026-66010",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66010"
        },
        {
          "name": "CVE-2026-63495",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63495"
        },
        {
          "name": "CVE-2024-45590",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-45590"
        },
        {
          "name": "CVE-2022-35961",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-35961"
        },
        {
          "name": "CVE-2026-19534",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19534"
        },
        {
          "name": "CVE-2026-34043",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34043"
        },
        {
          "name": "CVE-2024-43796",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-43796"
        },
        {
          "name": "CVE-2025-66031",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-66031"
        },
        {
          "name": "CVE-2026-59647",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59647"
        },
        {
          "name": "CVE-2024-4067",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-4067"
        },
        {
          "name": "CVE-2026-58059",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58059"
        },
        {
          "name": "CVE-2026-8763",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8763"
        },
        {
          "name": "CVE-2026-69247",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-69247"
        },
        {
          "name": "CVE-2026-33894",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33894"
        },
        {
          "name": "CVE-2025-68470",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68470"
        },
        {
          "name": "CVE-2026-69248",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-69248"
        },
        {
          "name": "CVE-2026-18446",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18446"
        },
        {
          "name": "CVE-2026-84292",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84292"
        },
        {
          "name": "CVE-2026-14802",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14802"
        },
        {
          "name": "CVE-2025-13466",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13466"
        },
        {
          "name": "CVE-2026-15055",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15055"
        },
        {
          "name": "CVE-2026-14682",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14682"
        },
        {
          "name": "CVE-2023-0842",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-0842"
        },
        {
          "name": "CVE-2026-59869",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59869"
        },
        {
          "name": "CVE-2025-71330",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-71330"
        },
        {
          "name": "CVE-2026-58061",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58061"
        },
        {
          "name": "CVE-2024-22195",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-22195"
        },
        {
          "name": "CVE-2018-14732",
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-14732"
        },
        {
          "name": "CVE-2024-21538",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-21538"
        },
        {
          "name": "CVE-2024-47764",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-47764"
        },
        {
          "name": "CVE-2026-6253",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6253"
        },
        {
          "name": "CVE-2026-47027",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47027"
        },
        {
          "name": "CVE-2026-47058",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47058"
        },
        {
          "name": "CVE-2026-49875",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49875"
        },
        {
          "name": "CVE-2026-18149",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18149"
        },
        {
          "name": "CVE-2026-16441",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16441"
        },
        {
          "name": "CVE-2026-33891",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33891"
        },
        {
          "name": "CVE-2026-58060",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58060"
        },
        {
          "name": "CVE-2018-1109",
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1109"
        },
        {
          "name": "CVE-2025-68146",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68146"
        },
        {
          "name": "CVE-2021-23382",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-23382"
        },
        {
          "name": "CVE-2025-66030",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-66030"
        },
        {
          "name": "CVE-2026-55603",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55603"
        },
        {
          "name": "CVE-2026-58063",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58063"
        },
        {
          "name": "CVE-2025-71329",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-71329"
        },
        {
          "name": "CVE-2026-70907",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-70907"
        },
        {
          "name": "CVE-2024-56201",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-56201"
        },
        {
          "name": "CVE-2026-63382",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63382"
        },
        {
          "name": "CVE-2026-47063",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47063"
        },
        {
          "name": "CVE-2026-12816",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12816"
        },
        {
          "name": "CVE-2026-59878",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59878"
        },
        {
          "name": "CVE-2026-63383",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63383"
        },
        {
          "name": "CVE-2026-84961",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84961"
        },
        {
          "name": "CVE-2026-13149",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13149"
        },
        {
          "name": "CVE-2025-30360",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-30360"
        },
        {
          "name": "CVE-2026-47021",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47021"
        },
        {
          "name": "CVE-2026-16440",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16440"
        },
        {
          "name": "CVE-2026-84933",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84933"
        },
        {
          "name": "CVE-2026-63380",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63380"
        },
        {
          "name": "CVE-2026-13506",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13506"
        },
        {
          "name": "CVE-2026-75899",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75899"
        },
        {
          "name": "CVE-2026-14631",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14631"
        },
        {
          "name": "CVE-2026-46968",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46968"
        },
        {
          "name": "CVE-2022-35948",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-35948"
        },
        {
          "name": "CVE-2026-9358",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9358"
        },
        {
          "name": "CVE-2026-75838",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75838"
        },
        {
          "name": "CVE-2018-14041",
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-14041"
        },
        {
          "name": "CVE-2026-63379",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63379"
        },
        {
          "name": "CVE-2024-37890",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-37890"
        },
        {
          "name": "CVE-2026-82562",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82562"
        },
        {
          "name": "CVE-2026-4873",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4873"
        },
        {
          "name": "CVE-2026-9678",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9678"
        },
        {
          "name": "CVE-2026-18540",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18540"
        },
        {
          "name": "CVE-2026-63385",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63385"
        },
        {
          "name": "CVE-2026-63387",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63387"
        },
        {
          "name": "CVE-2024-43800",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-43800"
        },
        {
          "name": "CVE-2026-16439",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16439"
        },
        {
          "name": "CVE-2026-85024",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85024"
        },
        {
          "name": "CVE-2026-61308",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-61308"
        },
        {
          "name": "CVE-2026-75931",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75931"
        },
        {
          "name": "CVE-2026-6276",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6276"
        },
        {
          "name": "CVE-2026-48779",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48779"
        },
        {
          "name": "CVE-2026-9563",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9563"
        },
        {
          "name": "CVE-2026-13676",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13676"
        },
        {
          "name": "CVE-2026-60589",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-60589"
        },
        {
          "name": "CVE-2026-53669",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53669"
        },
        {
          "name": "CVE-2026-6322",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6322"
        },
        {
          "name": "CVE-2026-8400",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8400"
        },
        {
          "name": "CVE-2026-45623",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45623"
        },
        {
          "name": "CVE-2026-58062",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58062"
        },
        {
          "name": "CVE-2025-30359",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-30359"
        },
        {
          "name": "CVE-2026-63381",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63381"
        },
        {
          "name": "CVE-2026-49356",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49356"
        },
        {
          "name": "CVE-2026-12803",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12803"
        },
        {
          "name": "CVE-2026-59650",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59650"
        },
        {
          "name": "CVE-2024-34064",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-34064"
        },
        {
          "name": "CVE-2026-45736",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45736"
        },
        {
          "name": "CVE-2026-71870",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-71870"
        },
        {
          "name": "CVE-2022-24771",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-24771"
        },
        {
          "name": "CVE-2026-71852",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-71852"
        },
        {
          "name": "CVE-2026-84890",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84890"
        },
        {
          "name": "CVE-2026-63388",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63388"
        },
        {
          "name": "CVE-2026-82397",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82397"
        },
        {
          "name": "CVE-2026-55602",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55602"
        },
        {
          "name": "CVE-2026-67213",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67213"
        },
        {
          "name": "CVE-2026-85062",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85062"
        },
        {
          "name": "CVE-2026-13586",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13586"
        },
        {
          "name": "CVE-2026-72848",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72848"
        },
        {
          "name": "CVE-2026-12590",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12590"
        },
        {
          "name": "CVE-2026-75975",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75975"
        },
        {
          "name": "CVE-2026-7168",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7168"
        },
        {
          "name": "CVE-2026-14620",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14620"
        },
        {
          "name": "CVE-2021-20066",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-20066"
        },
        {
          "name": "CVE-2026-15157",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15157"
        },
        {
          "name": "CVE-2022-37620",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-37620"
        },
        {
          "name": "CVE-2026-60147",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-60147"
        },
        {
          "name": "CVE-2026-13311",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13311"
        },
        {
          "name": "CVE-2020-7598",
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-7598"
        },
        {
          "name": "CVE-2026-33896",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33896"
        },
        {
          "name": "CVE-2026-47059",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47059"
        },
        {
          "name": "CVE-2026-16728",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16728"
        },
        {
          "name": "CVE-2026-84947",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84947"
        },
        {
          "name": "CVE-2019-8331",
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-8331"
        },
        {
          "name": "CVE-2026-73646",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73646"
        }
      ],
      "initial_release_date": "2026-09-25T00:00:00",
      "last_revision_date": "2026-09-25T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1233",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-25T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Injection de code indirecte \u00e0 distance (XSS)"
        },
        {
          "description": "Injection de requ\u00eates ill\u00e9gitimes par rebond (CSRF)"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
      "vendor_advisories": [
        {
          "published_at": "2026-09-23",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289042",
          "url": "https://www.ibm.com/support/pages/node/7289042"
        },
        {
          "published_at": "2026-09-21",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7288723",
          "url": "https://www.ibm.com/support/pages/node/7288723"
        },
        {
          "published_at": "2026-09-22",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7288869",
          "url": "https://www.ibm.com/support/pages/node/7288869"
        },
        {
          "published_at": "2026-09-22",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7288863",
          "url": "https://www.ibm.com/support/pages/node/7288863"
        },
        {
          "published_at": "2026-09-22",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7288871",
          "url": "https://www.ibm.com/support/pages/node/7288871"
        },
        {
          "published_at": "2026-09-22",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7288868",
          "url": "https://www.ibm.com/support/pages/node/7288868"
        },
        {
          "published_at": "2026-09-23",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289047",
          "url": "https://www.ibm.com/support/pages/node/7289047"
        },
        {
          "published_at": "2026-09-21",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7288650",
          "url": "https://www.ibm.com/support/pages/node/7288650"
        },
        {
          "published_at": "2026-09-24",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289363",
          "url": "https://www.ibm.com/support/pages/node/7289363"
        },
        {
          "published_at": "2026-09-24",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289341",
          "url": "https://www.ibm.com/support/pages/node/7289341"
        },
        {
          "published_at": "2026-09-21",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7288632",
          "url": "https://www.ibm.com/support/pages/node/7288632"
        },
        {
          "published_at": "2026-09-24",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7289320",
          "url": "https://www.ibm.com/support/pages/node/7289320"
        },
        {
          "published_at": "2026-09-22",
          "title": "Bulletin de s\u00e9curit\u00e9 IBM 7288873",
          "url": "https://www.ibm.com/support/pages/node/7288873"
        }
      ]
    }

    CVE-2026-84842 (GCVE-0-2026-84842)

    Vulnerability from nvd – Published: 2026-09-29 17:48 – Updated: 2026-09-29 21:02
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 20:53 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84842",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T20:53:59.779075Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T21:02:00.396Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:48:01.888Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84842",
        "datePublished": "2026-09-29T17:48:01.888Z",
        "dateReserved": "2026-09-02T12:06:32.240Z",
        "dateUpdated": "2026-09-29T21:02:00.396Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84440 (GCVE-0-2026-84440)

    Vulnerability from nvd – Published: 2026-09-29 17:51 – Updated: 2026-09-30 03:56
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 00:00 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84440",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T03:56:47.369Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:51:03.940Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84440",
        "datePublished": "2026-09-29T17:51:03.940Z",
        "dateReserved": "2026-09-01T19:28:01.914Z",
        "dateUpdated": "2026-09-30T03:56:47.369Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84436 (GCVE-0-2026-84436)

    Vulnerability from nvd – Published: 2026-09-29 17:53 – Updated: 2026-09-30 03:56
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 00:00 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288040 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84436",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T03:56:45.867Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:53:14.350Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288040"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84436",
        "datePublished": "2026-09-29T17:53:14.350Z",
        "dateReserved": "2026-09-01T19:14:00.582Z",
        "dateUpdated": "2026-09-30T03:56:45.867Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84422 (GCVE-0-2026-84422)

    Vulnerability from nvd – Published: 2026-09-29 17:55 – Updated: 2026-09-30 03:56
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 00:00 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288034 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84422",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T03:56:41.683Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:55:27.537Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288034"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84422",
        "datePublished": "2026-09-29T17:55:27.537Z",
        "dateReserved": "2026-09-01T17:54:27.939Z",
        "dateUpdated": "2026-09-30T03:56:41.683Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84421 (GCVE-0-2026-84421)

    Vulnerability from nvd – Published: 2026-09-29 17:57 – Updated: 2026-09-29 21:02
    VLAI
    Title
    DataStage on Cloud Pak for Data has several vulnerabilities
    Summary
    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 20:53 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288649 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM DataStage on Cloud Pak for Data Affected: 5.4.0.0 (custom)
        cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84421",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T20:53:23.987047Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T21:02:00.663Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*"
              ],
              "product": "DataStage on Cloud Pak for Data",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.4.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction.\u003c/p\u003e"
                }
              ],
              "value": "IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:57:20.631Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288649"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cp\u003e\u003cstrong\u003eIBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data.\u003c/strong\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003eProduct(s)\u003c/td\u003e\u003ctd\u003eVersion(s) number and/or range\u00a0\u003c/td\u003e\u003ctd\u003eRemediation/Fix/Instructions\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eDataStage on Cloud Pak for Data\u003c/td\u003e\u003ctd\u003e5.4.0.0\u003c/td\u003e\u003ctd\u003e\u003cp\u003eUpgrade to 5.4 patch 7 or later by following these \u003ca href=\"https://www.ibm.com/docs/en/software-hub/5.4.x?topic=overview-available-patches-software-hub-version-540\" rel=\"nofollow\"\u003einstructions\u003c/a\u003e.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003c/div\u003e"
                }
              ],
              "value": "IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data.\n\nProduct(s)Version(s) number and/or range\u00a0Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0\n\nUpgrade to 5.4 patch 7 or later by following these  instructions https://www.ibm.com/docs/en/software-hub/5.4.x ."
            }
          ],
          "title": "DataStage on Cloud Pak for Data has several vulnerabilities"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84421",
        "datePublished": "2026-09-29T17:57:20.631Z",
        "dateReserved": "2026-09-01T17:50:05.004Z",
        "dateUpdated": "2026-09-29T21:02:00.663Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84414 (GCVE-0-2026-84414)

    Vulnerability from nvd – Published: 2026-09-29 18:00 – Updated: 2026-09-30 03:56
    VLAI
    Title
    IBM i is Affected By An Incorrect Permission Assignment Vulnerability in Network Authentication Service []
    Summary
    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 00:00 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7289443 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM i Affected: 7.6 (custom)
    Affected: 7.5 (custom)
    Affected: 7.4 (custom)
    Affected: 7.3 (custom)
        cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84414",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T03:56:40.208Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"
              ],
              "product": "i",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.5",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.4",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.\u003c/p\u003e"
                }
              ],
              "value": "IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T18:00:05.613Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7289443"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003ctable\u003e\u003ccolgroup\u003e\u003ccol/\u003e\u003ccol/\u003e\u003ccol/\u003e\u003c/colgroup\u003e\u003cthead\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eIBM i Release\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e5770-SS1\u00a0\u003cbr/\u003ePTF Number(s)\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003ePTF Download Link(s)\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e7.6\u003c/td\u003e\u003ctd\u003eSJ11607\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11607\" rel=\"nofollow\"\u003ehttps://www.ibm.com/mysupport/s/fix-information?legacy=SJ11607\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e7.5\u003c/td\u003e\u003ctd\u003eSJ11608\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11608\" rel=\"nofollow\"\u003ehttps://www.ibm.com/mysupport/s/fix-information?legacy=SJ11608\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e7.4\u003c/td\u003e\u003ctd\u003eSJ11609\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11609\" rel=\"nofollow\"\u003ehttps://www.ibm.com/mysupport/s/fix-information?legacy=SJ11609\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e7.3\u003c/td\u003e\u003ctd\u003eSJ11610\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11610\" rel=\"nofollow\"\u003ehttps://www.ibm.com/mysupport/s/fix-information?legacy=SJ11610\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003eIBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.\u003c/p\u003e"
                }
              ],
              "value": "IBM i Release5770-SS1\u00a0\nPTF Number(s)PTF Download Link(s)7.6SJ11607 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11607 7.5SJ11608 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11608 7.4SJ11609 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11609 7.3SJ11610 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11610 \n\n\n\nIBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products."
            }
          ],
          "title": "IBM i is Affected By An Incorrect Permission Assignment Vulnerability in Network Authentication Service []"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84414",
        "datePublished": "2026-09-29T18:00:05.613Z",
        "dateReserved": "2026-09-01T17:35:17.124Z",
        "dateUpdated": "2026-09-30T03:56:40.208Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93030 (GCVE-0-2026-93030)

    Vulnerability from nvd – Published: 2026-09-25 14:32 – Updated: 2026-09-25 15:24
    VLAI
    Summary
    FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-25 15:24 UTC
    CWE
    • CWE-611 - Improper restriction of XML external entity reference
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93030",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-25T15:24:04.111638Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-25T15:24:11.046Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "IBM Financial Transaction Manager (FTM) for Redhat OpenShift",
              "vendor": "IBM",
              "versions": [
                {
                  "lessThanOrEqual": "4.0.10.0",
                  "status": "affected",
                  "version": "4.0.6.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw."
                }
              ],
              "value": "FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-611",
                  "description": "CWE-611 Improper restriction of XML external entity reference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T14:32:52.057Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "url": "https://www.ibm.com/support/pages/node/7288641"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cbr\u003eIBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following\u003c/p\u003e\u003cp\u003e\u0026nbsp;\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003eAffected Product(s)\u003c/td\u003e\u003ctd\u003eResolved by VRMF\u003c/td\u003e\u003ctd\u003eRemediation / First Fix\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eFinancial Transaction Manager (FTM)\u0026nbsp;for RedHat OpenShift\u003c/td\u003e\u003ctd\u003e4.0.11.0\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7285661\" rel=\"nofollow\"\u003eFTM 4.0.11.0\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cbr\u003e"
                }
              ],
              "value": "IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following\n\n\n\n\u00a0\n\nAffected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM)\u00a0for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-93030",
        "datePublished": "2026-09-25T14:32:52.057Z",
        "dateReserved": "2026-09-17T15:04:41.809Z",
        "dateUpdated": "2026-09-25T15:24:11.046Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84882 (GCVE-0-2026-84882)

    Vulnerability from nvd – Published: 2026-09-25 14:01 – Updated: 2026-09-26 03:55
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-25 00:00 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84882",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-25T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-26T03:55:50.883Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T14:01:24.872Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84882",
        "datePublished": "2026-09-25T14:01:24.872Z",
        "dateReserved": "2026-09-02T14:10:18.102Z",
        "dateUpdated": "2026-09-26T03:55:50.883Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84862 (GCVE-0-2026-84862)

    Vulnerability from nvd – Published: 2026-09-25 14:03 – Updated: 2026-09-28 12:39
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-26 03:55 UTC
    CWE
    • CWE-502 - Deserialization of Untrusted Data
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288040 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84862",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-26T03:55:50.546645Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T12:39:30.847Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502 Deserialization of Untrusted Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T14:03:36.973Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288040"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84862",
        "datePublished": "2026-09-25T14:03:36.973Z",
        "dateReserved": "2026-09-02T13:40:45.086Z",
        "dateUpdated": "2026-09-28T12:39:30.847Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85542 (GCVE-0-2026-85542)

    Vulnerability from nvd – Published: 2026-09-25 13:53 – Updated: 2026-09-27 03:55
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-25 00:00 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-85542",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-25T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-27T03:55:28.618Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T13:53:50.933Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\nProductVersions FixIBM Guardium Data Protection12.2https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-85542",
        "datePublished": "2026-09-25T13:53:50.933Z",
        "dateReserved": "2026-09-04T09:10:45.809Z",
        "dateUpdated": "2026-09-27T03:55:28.618Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85029 (GCVE-0-2026-85029)

    Vulnerability from nvd – Published: 2026-09-25 13:56 – Updated: 2026-09-28 12:40
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-26 03:55 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288034 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-85029",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-26T03:55:47.885059Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T12:40:11.842Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T13:56:47.103Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288034"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-85029",
        "datePublished": "2026-09-25T13:56:47.103Z",
        "dateReserved": "2026-09-02T20:02:31.650Z",
        "dateUpdated": "2026-09-28T12:40:11.842Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84893 (GCVE-0-2026-84893)

    Vulnerability from nvd – Published: 2026-09-25 13:58 – Updated: 2026-09-25 14:25
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-25 14:25 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84893",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-25T14:25:18.707832Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-25T14:25:26.625Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T13:58:30.382Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84893",
        "datePublished": "2026-09-25T13:58:30.382Z",
        "dateReserved": "2026-09-02T14:52:09.535Z",
        "dateUpdated": "2026-09-25T14:25:26.625Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84884 (GCVE-0-2026-84884)

    Vulnerability from nvd – Published: 2026-09-25 14:00 – Updated: 2026-09-28 12:39
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-26 03:55 UTC
    CWE
    • CWE-256 - Plaintext Storage of a Password
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84884",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-26T03:55:47.200811Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T12:39:44.729Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-256",
                  "description": "CWE-256 Plaintext Storage of a Password",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T14:00:02.737Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84884",
        "datePublished": "2026-09-25T14:00:02.737Z",
        "dateReserved": "2026-09-02T14:12:49.784Z",
        "dateUpdated": "2026-09-28T12:39:44.729Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-82094 (GCVE-0-2026-82094)

    Vulnerability from nvd – Published: 2026-09-24 14:29 – Updated: 2026-09-24 17:47
    VLAI
    Title
    DataStage on Cloud Pak for Data has several vulnerabilities
    Summary
    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 17:47 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288649 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM DataStage on Cloud Pak for Data Affected: 5.4.0.0
        cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-82094",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T17:47:12.811707Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T17:47:31.565Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*"
              ],
              "product": "DataStage on Cloud Pak for Data",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.4.0.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.\u003c/p\u003e"
                }
              ],
              "value": "IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T14:29:48.152Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288649"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cp\u003e\u003cstrong\u003eIBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data.\u003c/strong\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003eProduct(s)\u003c/td\u003e\u003ctd\u003eVersion(s) number and/or range\u00a0\u003c/td\u003e\u003ctd\u003eRemediation/Fix/Instructions\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eDataStage on Cloud Pak for Data\u003c/td\u003e\u003ctd\u003e5.4.0.0\u003c/td\u003e\u003ctd\u003e\u003cp\u003eUpgrade to 5.4 patch 7 or later by following these \u003ca href=\"https://www.ibm.com/docs/en/software-hub/5.4.x?topic=overview-available-patches-software-hub-version-540\" rel=\"nofollow\"\u003einstructions\u003c/a\u003e.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003c/div\u003e"
                }
              ],
              "value": "IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data.\n\nProduct(s)Version(s) number and/or range\u00a0Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0\n\nUpgrade to 5.4 patch 7 or later by following these  instructions https://www.ibm.com/docs/en/software-hub/5.4.x ."
            }
          ],
          "title": "DataStage on Cloud Pak for Data has several vulnerabilities"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-82094",
        "datePublished": "2026-09-24T14:29:48.152Z",
        "dateReserved": "2026-08-28T04:38:53.420Z",
        "dateUpdated": "2026-09-24T17:47:31.565Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-82093 (GCVE-0-2026-82093)

    Vulnerability from nvd – Published: 2026-09-24 14:29 – Updated: 2026-09-24 14:55
    VLAI
    Title
    DataStage on Cloud Pak for Data has several vulnerabilities
    Summary
    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 14:54 UTC
    CWE
    • CWE-502 - Deserialization of Untrusted Data
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288649 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM DataStage on Cloud Pak for Data Affected: 5.4.0.0
        cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-82093",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T14:54:51.145401Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T14:55:01.292Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*"
              ],
              "product": "DataStage on Cloud Pak for Data",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.4.0.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.\u003c/p\u003e"
                }
              ],
              "value": "IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502 Deserialization of Untrusted Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T14:29:04.849Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288649"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cp\u003e\u003cstrong\u003eIBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data.\u003c/strong\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003eProduct(s)\u003c/td\u003e\u003ctd\u003eVersion(s) number and/or range\u00a0\u003c/td\u003e\u003ctd\u003eRemediation/Fix/Instructions\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eDataStage on Cloud Pak for Data\u003c/td\u003e\u003ctd\u003e5.4.0.0\u003c/td\u003e\u003ctd\u003e\u003cp\u003eUpgrade to 5.4 patch 7 or later by following these \u003ca href=\"https://www.ibm.com/docs/en/software-hub/5.4.x?topic=overview-available-patches-software-hub-version-540\" rel=\"nofollow\"\u003einstructions\u003c/a\u003e.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003c/div\u003e"
                }
              ],
              "value": "IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data.\n\nProduct(s)Version(s) number and/or range\u00a0Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0\n\nUpgrade to 5.4 patch 7 or later by following these  instructions https://www.ibm.com/docs/en/software-hub/5.4.x ."
            }
          ],
          "title": "DataStage on Cloud Pak for Data has several vulnerabilities"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-82093",
        "datePublished": "2026-09-24T14:29:04.849Z",
        "dateReserved": "2026-08-28T04:36:58.456Z",
        "dateUpdated": "2026-09-24T14:55:01.292Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84414 (GCVE-0-2026-84414)

    Vulnerability from cvelistv5 – Published: 2026-09-29 18:00 – Updated: 2026-09-30 03:56
    VLAI
    Title
    IBM i is Affected By An Incorrect Permission Assignment Vulnerability in Network Authentication Service []
    Summary
    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 00:00 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7289443 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM i Affected: 7.6 (custom)
    Affected: 7.5 (custom)
    Affected: 7.4 (custom)
    Affected: 7.3 (custom)
        cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84414",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T03:56:40.208Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"
              ],
              "product": "i",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.5",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.4",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.\u003c/p\u003e"
                }
              ],
              "value": "IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T18:00:05.613Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7289443"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003ctable\u003e\u003ccolgroup\u003e\u003ccol/\u003e\u003ccol/\u003e\u003ccol/\u003e\u003c/colgroup\u003e\u003cthead\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eIBM i Release\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e5770-SS1\u00a0\u003cbr/\u003ePTF Number(s)\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003ePTF Download Link(s)\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e7.6\u003c/td\u003e\u003ctd\u003eSJ11607\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11607\" rel=\"nofollow\"\u003ehttps://www.ibm.com/mysupport/s/fix-information?legacy=SJ11607\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e7.5\u003c/td\u003e\u003ctd\u003eSJ11608\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11608\" rel=\"nofollow\"\u003ehttps://www.ibm.com/mysupport/s/fix-information?legacy=SJ11608\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e7.4\u003c/td\u003e\u003ctd\u003eSJ11609\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11609\" rel=\"nofollow\"\u003ehttps://www.ibm.com/mysupport/s/fix-information?legacy=SJ11609\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e7.3\u003c/td\u003e\u003ctd\u003eSJ11610\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11610\" rel=\"nofollow\"\u003ehttps://www.ibm.com/mysupport/s/fix-information?legacy=SJ11610\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003eIBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.\u003c/p\u003e"
                }
              ],
              "value": "IBM i Release5770-SS1\u00a0\nPTF Number(s)PTF Download Link(s)7.6SJ11607 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11607 7.5SJ11608 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11608 7.4SJ11609 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11609 7.3SJ11610 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11610 \n\n\n\nIBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products."
            }
          ],
          "title": "IBM i is Affected By An Incorrect Permission Assignment Vulnerability in Network Authentication Service []"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84414",
        "datePublished": "2026-09-29T18:00:05.613Z",
        "dateReserved": "2026-09-01T17:35:17.124Z",
        "dateUpdated": "2026-09-30T03:56:40.208Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84421 (GCVE-0-2026-84421)

    Vulnerability from cvelistv5 – Published: 2026-09-29 17:57 – Updated: 2026-09-29 21:02
    VLAI
    Title
    DataStage on Cloud Pak for Data has several vulnerabilities
    Summary
    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 20:53 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288649 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM DataStage on Cloud Pak for Data Affected: 5.4.0.0 (custom)
        cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84421",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T20:53:23.987047Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T21:02:00.663Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*"
              ],
              "product": "DataStage on Cloud Pak for Data",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.4.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction.\u003c/p\u003e"
                }
              ],
              "value": "IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:57:20.631Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288649"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cp\u003e\u003cstrong\u003eIBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data.\u003c/strong\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003eProduct(s)\u003c/td\u003e\u003ctd\u003eVersion(s) number and/or range\u00a0\u003c/td\u003e\u003ctd\u003eRemediation/Fix/Instructions\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eDataStage on Cloud Pak for Data\u003c/td\u003e\u003ctd\u003e5.4.0.0\u003c/td\u003e\u003ctd\u003e\u003cp\u003eUpgrade to 5.4 patch 7 or later by following these \u003ca href=\"https://www.ibm.com/docs/en/software-hub/5.4.x?topic=overview-available-patches-software-hub-version-540\" rel=\"nofollow\"\u003einstructions\u003c/a\u003e.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003c/div\u003e"
                }
              ],
              "value": "IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data.\n\nProduct(s)Version(s) number and/or range\u00a0Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0\n\nUpgrade to 5.4 patch 7 or later by following these  instructions https://www.ibm.com/docs/en/software-hub/5.4.x ."
            }
          ],
          "title": "DataStage on Cloud Pak for Data has several vulnerabilities"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84421",
        "datePublished": "2026-09-29T17:57:20.631Z",
        "dateReserved": "2026-09-01T17:50:05.004Z",
        "dateUpdated": "2026-09-29T21:02:00.663Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84422 (GCVE-0-2026-84422)

    Vulnerability from cvelistv5 – Published: 2026-09-29 17:55 – Updated: 2026-09-30 03:56
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 00:00 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288034 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84422",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T03:56:41.683Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:55:27.537Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288034"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84422",
        "datePublished": "2026-09-29T17:55:27.537Z",
        "dateReserved": "2026-09-01T17:54:27.939Z",
        "dateUpdated": "2026-09-30T03:56:41.683Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84436 (GCVE-0-2026-84436)

    Vulnerability from cvelistv5 – Published: 2026-09-29 17:53 – Updated: 2026-09-30 03:56
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 00:00 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288040 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84436",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T03:56:45.867Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:53:14.350Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288040"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84436",
        "datePublished": "2026-09-29T17:53:14.350Z",
        "dateReserved": "2026-09-01T19:14:00.582Z",
        "dateUpdated": "2026-09-30T03:56:45.867Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84440 (GCVE-0-2026-84440)

    Vulnerability from cvelistv5 – Published: 2026-09-29 17:51 – Updated: 2026-09-30 03:56
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 00:00 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84440",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T03:56:47.369Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:51:03.940Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84440",
        "datePublished": "2026-09-29T17:51:03.940Z",
        "dateReserved": "2026-09-01T19:28:01.914Z",
        "dateUpdated": "2026-09-30T03:56:47.369Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84842 (GCVE-0-2026-84842)

    Vulnerability from cvelistv5 – Published: 2026-09-29 17:48 – Updated: 2026-09-29 21:02
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 20:53 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84842",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T20:53:59.779075Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T21:02:00.396Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:48:01.888Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84842",
        "datePublished": "2026-09-29T17:48:01.888Z",
        "dateReserved": "2026-09-02T12:06:32.240Z",
        "dateUpdated": "2026-09-29T21:02:00.396Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93030 (GCVE-0-2026-93030)

    Vulnerability from cvelistv5 – Published: 2026-09-25 14:32 – Updated: 2026-09-25 15:24
    VLAI
    Summary
    FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-25 15:24 UTC
    CWE
    • CWE-611 - Improper restriction of XML external entity reference
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93030",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-25T15:24:04.111638Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-25T15:24:11.046Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "IBM Financial Transaction Manager (FTM) for Redhat OpenShift",
              "vendor": "IBM",
              "versions": [
                {
                  "lessThanOrEqual": "4.0.10.0",
                  "status": "affected",
                  "version": "4.0.6.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw."
                }
              ],
              "value": "FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-611",
                  "description": "CWE-611 Improper restriction of XML external entity reference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T14:32:52.057Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "url": "https://www.ibm.com/support/pages/node/7288641"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cbr\u003eIBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following\u003c/p\u003e\u003cp\u003e\u0026nbsp;\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003eAffected Product(s)\u003c/td\u003e\u003ctd\u003eResolved by VRMF\u003c/td\u003e\u003ctd\u003eRemediation / First Fix\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eFinancial Transaction Manager (FTM)\u0026nbsp;for RedHat OpenShift\u003c/td\u003e\u003ctd\u003e4.0.11.0\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7285661\" rel=\"nofollow\"\u003eFTM 4.0.11.0\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cbr\u003e"
                }
              ],
              "value": "IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following\n\n\n\n\u00a0\n\nAffected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM)\u00a0for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-93030",
        "datePublished": "2026-09-25T14:32:52.057Z",
        "dateReserved": "2026-09-17T15:04:41.809Z",
        "dateUpdated": "2026-09-25T15:24:11.046Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84862 (GCVE-0-2026-84862)

    Vulnerability from cvelistv5 – Published: 2026-09-25 14:03 – Updated: 2026-09-28 12:39
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-26 03:55 UTC
    CWE
    • CWE-502 - Deserialization of Untrusted Data
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288040 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84862",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-26T03:55:50.546645Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T12:39:30.847Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502 Deserialization of Untrusted Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T14:03:36.973Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288040"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84862",
        "datePublished": "2026-09-25T14:03:36.973Z",
        "dateReserved": "2026-09-02T13:40:45.086Z",
        "dateUpdated": "2026-09-28T12:39:30.847Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84882 (GCVE-0-2026-84882)

    Vulnerability from cvelistv5 – Published: 2026-09-25 14:01 – Updated: 2026-09-26 03:55
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-25 00:00 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84882",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-25T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-26T03:55:50.883Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T14:01:24.872Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84882",
        "datePublished": "2026-09-25T14:01:24.872Z",
        "dateReserved": "2026-09-02T14:10:18.102Z",
        "dateUpdated": "2026-09-26T03:55:50.883Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84884 (GCVE-0-2026-84884)

    Vulnerability from cvelistv5 – Published: 2026-09-25 14:00 – Updated: 2026-09-28 12:39
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-26 03:55 UTC
    CWE
    • CWE-256 - Plaintext Storage of a Password
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84884",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-26T03:55:47.200811Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T12:39:44.729Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-256",
                  "description": "CWE-256 Plaintext Storage of a Password",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T14:00:02.737Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84884",
        "datePublished": "2026-09-25T14:00:02.737Z",
        "dateReserved": "2026-09-02T14:12:49.784Z",
        "dateUpdated": "2026-09-28T12:39:44.729Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84893 (GCVE-0-2026-84893)

    Vulnerability from cvelistv5 – Published: 2026-09-25 13:58 – Updated: 2026-09-25 14:25
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-25 14:25 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84893",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-25T14:25:18.707832Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-25T14:25:26.625Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T13:58:30.382Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-84893",
        "datePublished": "2026-09-25T13:58:30.382Z",
        "dateReserved": "2026-09-02T14:52:09.535Z",
        "dateUpdated": "2026-09-25T14:25:26.625Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85029 (GCVE-0-2026-85029)

    Vulnerability from cvelistv5 – Published: 2026-09-25 13:56 – Updated: 2026-09-28 12:40
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-26 03:55 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288034 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-85029",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-26T03:55:47.885059Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T12:40:11.842Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T13:56:47.103Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288034"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-85029",
        "datePublished": "2026-09-25T13:56:47.103Z",
        "dateReserved": "2026-09-02T20:02:31.650Z",
        "dateUpdated": "2026-09-28T12:40:11.842Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85542 (GCVE-0-2026-85542)

    Vulnerability from cvelistv5 – Published: 2026-09-25 13:53 – Updated: 2026-09-27 03:55
    VLAI
    Title
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Summary
    IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-25 00:00 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    URL Tags
    https://www.ibm.com/support/pages/node/7288035 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    IBM Guardium Data Protection Affected: 12.2 (custom)
        cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
        cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-85542",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-25T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-27T03:55:28.618Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"
              ],
              "product": "Guardium Data Protection",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager.\u003c/p\u003e"
                }
              ],
              "value": "IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T13:53:50.933Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://www.ibm.com/support/pages/node/7288035"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM encourages customers to update their systems promptly.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Product\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eVersions\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003e\u00a0Fix\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eIBM Guardium Data Protection\u003c/td\u003e\u003ctd\u003e12.2\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026amp;product=ibm/Information+Management/InfoSphere+Guardium\u0026amp;release=12.2\u0026amp;platform=Linux\u0026amp;function=fixId\u0026amp;fixids=SqlGuard_12.0p233_FixPack\u0026amp;includeSupersedes=0\u0026amp;source=fc\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "IBM encourages customers to update their systems promptly.\nProductVersions FixIBM Guardium Data Protection12.2https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security\u0026product=ibm/Information+Management/InfoSphere+Guardium\u0026release=12.2\u0026platform=Linux\u0026function=fixId\u0026fixids=SqlGuard_12.0p233_FixPack\u0026includeSupersedes=0\u0026source=fc"
            }
          ],
          "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2026-85542",
        "datePublished": "2026-09-25T13:53:50.933Z",
        "dateReserved": "2026-09-04T09:10:45.809Z",
        "dateUpdated": "2026-09-27T03:55:28.618Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }