PT-2026-95626 · Ibm · Guardium Data Protection
CVE-2026-81657
·
Published
2026-09-18
·
Updated
2026-09-26
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Guardium Data Protection version 12.2
Description
A remote unauthenticated attacker can execute arbitrary code on the system. This occurs due to the deserialization of untrusted data, which allows a network attacker who can reach the appliance to run code without requiring a login.
Recommendations
Apply the IBM fix packs released on September 17 for version 12.2.
Keep collectors and consoles off the public internet.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Guardium Data Protection