OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-84884

HIGH · CVSS 7.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

IBM Guardium Data Protection 12.2 is vulnerable due to the storage of internal REST service-account passwords in a reversible plaintext-equivalent format, allowing authenticated attackers to recover these credentials. This could lead to unauthorized administrative access via REST tokens, posing a significant risk to data security. Organizations using this version of Guardium should prioritize remediation to protect sensitive data and maintain system integrity.

CVE
CVE-2026-84884
Severity
HIGH
CVSS
7.5
EPSS
0.24%

Original NVD Description

IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.