Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.1
CVE-2026-84244: IBM Guardium Data Protection can run malicious browser scripts
CVE-2026-84244 · published 3 days ago
Summary
The Quick Search results grid in IBM Guardium Data Protection version 12.2 lets an attacker place hidden code that runs in the browser of a signed‑in user. If someone can tamper with the data flowing through the monitored databases, they could cause the user’s browser to execute that code, potentially stealing information or taking actions as that user. Apply the vendor’s security update or upgrade to a patched version and limit who can influence the monitored traffic.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | guardium data protection | 12.2 |
| ibm | guardium_data_protection |
12.2 cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:* |
Original advisory text
IBM Guardium Data Protection Cross-Site Scripting
IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute malicious script in the browser of an authenticated Guardium user.
References
- https://www.ibm.com/support/pages/node/7288035 Vendor Advisory
Internet-facing
60 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker partial control
Severity
6.1
Medium
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published8 Oct 2026
Updated11 Oct 2026
First seen8 Oct 2026
Track software like this
Free during beta