PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84274 IBM CVE debrief

IBM Guardium Data Protection 12.2.2 is affected by an information disclosure vulnerability. During SECRET and API_KEY rotation processing, sensitive credential material is logged at INFO level by the edge-controller/edge-manager components. An authenticated attacker with access to the relevant application or container logs could obtain these credentials and use them to impersonate services or gain unauthorized access to the Guardium control plane.

Vendor
IBM
Product
Guardium Data Protection
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for IBM Guardium Data Protection deployments, especially those with access to application or container logs, should assess exposure and prioritize mitigation.

Why it matters

This information disclosure vulnerability in IBM Guardium Data Protection 12.2.2 allows authenticated attackers with access to logs to obtain sensitive credentials, potentially leading to unauthorized access or impersonation. Defenders should prioritize verification and mitigation, especially in deployments with accessible logs.

  • Potential unauthorized access to the Guardium control plane
  • Impersonation of services using obtained credentials
  • Elevation of privileges for authenticated attackers
  • Compromise of sensitive credential material

Technical summary

IBM Guardium Data Protection 12.2.2 is vulnerable to information disclosure due to sensitive credential material being logged at INFO level during SECRET and API_KEY rotation processing. An authenticated attacker with access to relevant logs could obtain credentials to impersonate services or gain unauthorized access to the Guardium control plane. This vulnerability allows potential unauthorized access or impersonation, emphasizing the need for defenders to prioritize verification and mitigation, especially in deployments with accessible logs.

Defensive priority

Defenders should prioritize verifying and mitigating this vulnerability in IBM Guardium Data Protection 12.2.2 deployments, especially those with access to application or container logs.

Recommended defensive actions

  • Verify IBM Guardium Data Protection 12.2.2 deployments for potential exposure
  • Restrict access to application and container logs
  • Consider upgrading to a non-affected version if available
  • Monitor for unauthorized access attempts on the Guardium control plane
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, affected version, and potential impact. However, additional information on exploitation, victims, or remediation is limited. Defenders should verify logs for exposed credentials and assess potential unauthorized access or impersonation risks. Limited source information is available for further analysis.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84274 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84274

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84274 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84274

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • IBM Guardium Data Protection Information Disclosure

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/84xxx/CVE-2026-84274.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://www.ibm.com/support/pages/node/7288627

    Supplemental source - vendor-advisory, patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.