IBM Guardium Data Protection: critical unauthenticated flaws in the Sniffer and Edge components, including path traversal to code execution and SQL injection (CVSS 9.8) and an edge-controller with no authentication that can run arbitrary containers (CVE-2026-84272, 9.8)
IBM published two security bulletins on 8 October 2026 for IBM Guardium Data Protection, the database activity monitoring platform whose collectors sit on the network and inspect database traffic. The Sniffer bulletin (versions 12.0, 12.1 and 12.2) fixes CVE-2026-75875 (CVSS 9.8, path traversal allowing remote code execution), CVE-2026-80381 (9.8) and CVE-2026-81932 (8.6, unauthenticated SQL injection), and several memory-corruption bugs in the traffic parsers, including a MongoDB SCRAM username overflow (CVE-2026-82335, 8.1) and a Microsoft SQL Server TDS PRELOGIN overflow (CVE-2026-84058, 8.1) that a remote attacker could trigger simply by sending crafted packets across a network the collector monitors. The Edge bulletin fixes CVE-2026-84272 (9.8): the edge-controller in 12.1 and 12.2.2 lacks authentication, so an unauthenticated remote attacker could run arbitrary container images and take control of managed edge clusters. The CVE records were published on 8 October; a related September bulletin also fixed CVE-2026-84249 (9.8, missing authentication for management operations in 12.2 and 12.2.2). IBM lists no workarounds and no exploitation. Primary: IBM.
- Product
- IBM Guardium Data Protection — Sniffer (collector), Edge component and appliance
- Versions
- Sniffer: 12.0, 12.1, 12.2; CVE-2026-84272: 12.1 and 12.2.2 (Edge component 12.2.2, appliance 12.1); CVE-2026-84249: 12.2 and 12.2.2
- CVSS
- (CVE-2026-75875, CVE-2026-80381, CVE-2026-84272, CVE-2026-84249); 8.6 (CVE-2026-81932); 8.1 (CVE-2026-82335, CVE-2026-84058)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Apply the latest Guardium Sniffer update (SqlGuard_12.0p4018_SnifferUpdate), Edge patch 12.0p15004 and fix pack 12.0p147 from IBM Fix Central (12.0p233 for CVE-2026-84249 on 12.2). No workaround exists; limit who can reach collector and edge-controller management ports in the meantime.
Primary: IBM — Security Bulletin: multiple vulnerabilities addressed in the Sniffer component of IBM Guardium Data Protection (8 Oct 2026) · Vendor: IBM — Security Bulletin: IBM Guardium Data Protection Edge component, CVE-2026-84272 (8 Oct 2026) · CVE: CVE-2026-84272, CVE-2026-75875, CVE-2026-80381, CVE-2026-81932, CVE-2026-82335, CVE-2026-84058, CVE-2026-84249 · IBM — Security Bulletin: IBM Guardium Data Protection, CVE-2026-84249 (17 Sep 2026)
