{"id":"CVE-2026-82340","published":"2026-09-18T20:17:24.517","lastModified":"2026-09-23T04:17:53.390","description":"IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288040","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to exploit insecure deserialization and reflective method dispatch, potentially leading to code execution on the IBM Guardium appliance.","exploitability":"Exploitation requires network access to TCP port 16017 and the ability to submit crafted serialized messages. Precondition is the absence of proper input validation and sanitization.","blast_radius":"If exploited, the attack could lead to full control over the Guardium appliance, compromising sensitive data and system integrity.","remediation":"Disable the Change Audit System (CAS) listener or upgrade to the latest version of IBM Guardium Data Protection 12.2.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","unauth","tcp","deserialization"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:57:50.393Z"}}