---
id: CVE-2026-84862
title: >-
  IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in
  the Quartz JDBC job store
summary: >-
  IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in
  the Quartz JDBC job store. An authenticated attacker could exploit this
  vulnerability to execute arbitrary code on the affected system.
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: IBM
product: Guardium Data Protection
affected:
  - guardium_data_protection 12.2
published: '2026-09-25'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T04:17:47.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84862'
references:
  - url: 'https://www.ibm.com/support/pages/node/7288040'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-25T00:00:00+00:00'
ingestedAt: '2026-09-25T15:10:56.371Z'
---

## Overview

IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
