{"id":"CVE-2026-84842","title":"IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component","summary":"IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denia…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-22"],"vendor":"IBM","product":"Guardium Data Protection","affected":["guardium_data_protection 12.2"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T18:17:18.083","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84842","references":[{"url":"https://www.ibm.com/support/pages/node/7288035","label":"psirt@us.ibm.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T18:42:35.822Z","slug":"CVE-2026-84842","body":"## Overview\n\nIBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}