Summary
CVE-2026-84035 is a stack-based buffer overflow (CWE-121) in IBM Guardium Data Protection versions 12.0, 12.1 and 12.2. A remote attacker could exploit it to execute arbitrary code. It is rated High severity (CVSS v3.1 8.1).
Technical details
- Root cause: stack-based buffer overflow (CWE-121) in IBM Guardium Data Protection. IBM’s remediation is delivered as a Sniffer patch.
- Trigger conditions: the CVSS vector rates attack complexity as High. No privileges or user interaction are required.
- Attack vector: network.
- Impact: remote arbitrary code execution. The vector rates confidentiality, integrity and availability impact as High.
Affected software
- IBM Guardium Data Protection 12.0
- IBM Guardium Data Protection 12.1
- IBM Guardium Data Protection 12.2
Severity
CVSS v3.1 base score 8.1 (High): CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the latest Guardium Data Protection Sniffer patch from IBM Fix Central. IBM’s bulletin references
SqlGuard_12.0p4018_SnifferUpdate. - Workarounds: IBM’s bulletin documents none. As general hardening, restrict network access to Guardium systems to trusted networks only.

