CVE-2026-85029High· 7.5▾ TwilightIBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84882High· 7.5IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component
CVE-2026-84086High· 7.2IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
CVE-2026-82896High· 7.6IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.
CVE-2026-84862High· 7.2IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store
CVE-2026-85542High· 8.8IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality
CVE-2026-84884High· 7.5IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format