---
id: CVE-2026-84882
title: >-
  IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the
  Universal Connector Oracle Wallet upload component
summary: >-
  IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the
  Universal Connector Oracle Wallet upload component. An authenticated remote
  attacker could exploit this vulnerability to write arbitrary files to the
  system.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: IBM
product: Guardium Data Protection
affected:
  - guardium_data_protection 12.2
published: '2026-09-25'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T04:17:48.000'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84882'
references:
  - url: 'https://www.ibm.com/support/pages/node/7288035'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-25T14:29:30.663305Z'
ingestedAt: '2026-09-25T15:10:56.369Z'
---

## Overview

IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
