← Back to search

CVE-2026-84034

8.8 HIGH

Published 2026-09-18 · Updated 2026-09-23

AI risk analysis

Summary
The flaw is a hardcoded credentials vulnerability in IBM Guardium Data Protection 12.2, allowing low-privileged authenticated users to recover sensitive secrets, potentially leading to unauthorized access and data compromise.
Exploitability
Exploitation is relatively straightforward for a low-privileged authenticated user, requiring access to the hardware_assess/obstore binaries.
Blast radius
If exploited, this vulnerability could result in unauthorized access to the internal database and compromise of sensitive system information.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to IBM Guardium Data Protection 12.2.1 or later.
auth-bypasshardcoded-credentialsdata-compromise

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-798

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.