CVE-2026-84884

Summary

IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.

Affected Software

VendorProductVersion RangeStatus
IBMGuardium Data Protection12.2affected

Weaknesses

  • CWE-256: CWE-256 Plaintext Storage of a Password

References