Summary
CVE-2026-84246 is a classic buffer overflow vulnerability (CWE-120) in IBM Guardium Data Protection 12.0, 12.1, and 12.2. It could allow a remote attacker to execute arbitrary code. The CVSS v3.1 base score is 8.1 (High).
Technical details
- Root cause: buffer copy without checking the size of the input (CWE-120, classic buffer overflow).
- Trigger conditions: the CVSS vector indicates high attack complexity, with no privileges and no user interaction required.
- Attack vector: network.
- Impact: a remote attacker could execute arbitrary code, with high impact on confidentiality, integrity, and availability.
Affected software
- IBM Guardium Data Protection 12.0
- IBM Guardium Data Protection 12.1
- IBM Guardium Data Protection 12.2
Severity
- CVSS v3.1 base score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: IBM recommends applying the latest IBM Guardium Data Protection Sniffer patch (for example,
SqlGuard_12.0p4018_SnifferUpdate) from IBM Fix Central, as described in the IBM security bulletin. - Workarounds: the IBM bulletin lists none. Until the patch is applied, limit network exposure of Guardium Data Protection systems to trusted networks only.

