CVE-2026-84244
Awaiting Analysis Awaiting Analysis - Queue

Stored XSS in IBM Guardium Data Protection

Vulnerability report for CVE-2026-84244, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: IBM Corporation

Description

IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute malicious script in the browser of an authenticated Guardium user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
IBM Guardium Data Protection 12.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Guardium Data Protection 12.2 has a stored cross-site scripting (XSS) vulnerability in the Quick Search results grid. An unauthenticated attacker can inject malicious scripts by influencing monitored database traffic, which then executes in the browser of an authenticated Guardium user.

Detection Guidance

This vulnerability involves stored XSS in IBM Guardium Data Protection's Quick Search results grid. Detection requires checking for unauthorized script execution in authenticated user sessions. Monitor Guardium logs for suspicious database traffic influencing search results. No specific commands are provided in the context.

Impact Analysis

This vulnerability allows an attacker to execute malicious scripts in the context of an authenticated user's session. This could lead to unauthorized actions, data theft, or session hijacking if the user has elevated privileges.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized script execution in authenticated users' browsers. This may lead to data exposure or manipulation, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Apply IBM's official patch or update for Guardium Data Protection 12.2. Restrict network access to Guardium interfaces to trusted sources only. Monitor and filter database traffic for malicious payloads. Review and sanitize Quick Search results output to prevent script execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84244. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart