Skip to content
IBMCVE-2026-84842

IBM Guardium Data Protection: path traversal

High8.1CVE-2026-84842 · Published Sep 29, 2026 · updated Oct 1, 2026

IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.

IBM advisory

Affected versions

PackageAffectedFixed in
Guardium Data Protection
Product
<= 12.2No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22

More IBM advisories

All IBM
Advisory
IBM i: insecure permissions
High7.8Sep 29
IBM DataStage on Cloud Pak for Data: remote code execution
High8.8Sep 29
IBM Guardium Data Protection: command injection
High7.2Sep 29
IBM Guardium Data Protection: command injection
Critical9.1Sep 29
IBM Guardium Data Protection: command injection
High7.5Sep 29
IBM Guardium Data Protection: unsafe deserialization
High7.2Sep 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.