---
id: CVE-2026-84842
title: >-
  IBM Guardium Data Protection 12.2 is vulnerable to path traversal and
  arbitrary file deletion in the Datasource REST component
summary: >-
  IBM Guardium Data Protection 12.2 is vulnerable to path traversal and
  arbitrary file deletion in the Datasource REST component. An authenticated
  remote attacker could exploit this vulnerability to delete files and
  potentially cause denia…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-22
vendor: IBM
product: Guardium Data Protection
affected:
  - guardium_data_protection 12.2
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T18:17:18.083'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84842'
references:
  - url: 'https://www.ibm.com/support/pages/node/7288035'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T18:42:35.822Z'
---

## Overview

IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
