{"dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": {"cveId": "CVE-2026-84882", "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "state": "PUBLISHED", "assignerShortName": "ibm", "dateReserved": "2026-09-02T14:10:18.102Z", "datePublished": "2026-09-25T14:01:24.872Z", "dateUpdated": "2026-09-25T14:31:16.228Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm", "dateUpdated": "2026-09-25T14:01:24.872Z"}, "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.", "problemTypes": [{"descriptions": [{"lang": "en", "cweId": "CWE-22", "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')", "type": "CWE"}]}], "affected": [{"vendor": "IBM", "product": "Guardium Data Protection", "versions": [{"status": "affected", "version": "12.2", "versionType": "custom"}], "cpes": ["cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"]}], "descriptions": [{"lang": "en", "value": "IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.", "supportingMedia": [{"type": "text/html", "base64": false, "value": "<p>IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.</p>"}]}], "references": [{"url": "https://www.ibm.com/support/pages/node/7288035", "tags": ["vendor-advisory", "patch"]}], "metrics": [{"format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}], "cvssV3_1": {"version": "3.1", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseSeverity": "HIGH", "baseScore": 7.5, "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}}], "solutions": [{"lang": "en", "value": "IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u00a0ProductVersions\u00a0FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc", "supportingMedia": [{"type": "text/html", "base64": false, "value": "<div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><p>IBM encourages customers to update their systems promptly.</p></div></div></div></div></div></div></div><div><div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><div><table><tbody><tr><td><strong>\u00a0Product</strong></td><td><strong>Versions</strong></td><td><strong>\u00a0Fix</strong></td></tr><tr><td>IBM Guardium Data Protection</td><td>12.2</td><td><a href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&amp;product=ibm/Information+Management/InfoSphere+Guardium&amp;release=12.2&amp;platform=Linux&amp;function=fixId&amp;fixids=SqlGuard_12.0p233_FixPack&amp;includeSupersedes=0&amp;source=fc\" rel=\"nofollow\">https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&amp;product=ibm/Information+Management/InfoSphere+Guardium&amp;release=12.2&amp;platform=Linux&amp;function=fixId&amp;fixids=SqlGuard_12.0p233_FixPack&amp;includeSupersedes=0&amp;source=fc</a></td></tr></tbody></table></div></div></div><p></p>"}]}]}, "adp": [{"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2026-09-25T14:29:30.663305Z", "id": "CVE-2026-84882", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "total"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-25T14:31:16.228Z"}}]}}