IBMCVE-2026-84422
IBM Guardium Data Protection: command injection
High7.2CVE-2026-84422 · Published Sep 29, 2026 · updated Oct 2, 2026
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Guardium Data Protection Product | <= 12.2 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | IBM Guardium Data Protection: path traversal | High8.1 | No fix yet |
| Sep 29 | IBM i: insecure permissions | High7.8 | No fix yet |
| Sep 29 | IBM DataStage on Cloud Pak for Data: remote code execution | High8.8 | No fix yet |
| Sep 29 | IBM Guardium Data Protection: command injection | Critical9.1 | No fix yet |
| Sep 29 | IBM Guardium Data Protection: command injection | High7.5 | No fix yet |
| Sep 25 | IBM Guardium Data Protection: unsafe deserialization | High7.2 | No fix yet |