PatchSiren cyber security CVE debrief
CVE-2026-87980 IBM CVE debrief
IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 have a vulnerability in the UNIX S-TAP component, allowing local attackers to obtain sensitive information due to cleartext storage of sensitive information in logs. The vulnerability has a CVSS score of 3.1 and is considered low severity. Defenders should assess exposure, prioritize log storage verification, and review access controls, especially in environments with local access concerns. The CVE record and source item provide details, but additional information on exploitation or affected systems is limited.
- Vendor
- IBM
- Product
- Guardium Data Protection
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for IBM Guardium Data Protection instances, especially those with local access concerns, should assess exposure and prioritize log storage verification and access control reviews.
Why it matters
Defenders should prioritize verifying log storage and reviewing access controls for Guardium Data Protection instances, especially in environments where local access is a concern, as the vulnerability could allow local attackers to obtain sensitive data.
- Verify log storage and access controls to prevent sensitive information exposure
- Review incident response plans for potential log-related security incidents
- Monitor system logs for sensitive information exposure
Technical summary
IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 store sensitive information in cleartext logs, potentially allowing local attackers to obtain sensitive data. The vulnerability has a CVSS score of 3.1 and is considered low severity. Defenders should prioritize verifying log storage and reviewing access controls for Guardium Data Protection instances, especially in environments where local access is a concern.
Defensive priority
Defenders should prioritize verifying log storage and reviewing access controls for Guardium Data Protection instances, especially in environments where local access is a concern.
Recommended defensive actions
- Verify log storage and access controls for Guardium Data Protection instances
- Review and update incident response plans for potential log-related security incidents
- Monitor system logs for sensitive information exposure
Evidence notes
The CVE record and source item provide details on the vulnerability, but additional information on exploitation or affected systems is limited. Defenders should verify log storage and access controls for Guardium Data Protection instances, review incident response plans for potential log-related security incidents, and monitor system logs for sensitive information exposure. The source item and CVE record have limited information on affected scope and exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87980 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87980
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87980 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87980
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Security vulnerability affects the UNIX S-TAP component as part of IBM Guardium Data Protection
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/87xxx/CVE-2026-87980.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7291672
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.