Description


IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of managed edge clusters.

Related CPE's


a

ibm

guardium_data_protection

2

Weaknesses



CWE-306

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-10-08T20:17:37.753Z

20 hours ago

Last modified

2026-10-09T14:18:05.077Z

2 hours ago