← Vulnerability feed

Vulnerability record · CVE-2025-36020 · published 6 August 2025

CVE-2025-36020: Ibm guardium data protection cleartext transmission vulnerability

Ibm · Guardium Data Protection

IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.

7.5 CVSS 3.1 High EPSS 0.21% · top 89.5% CWE-319 · Cleartext transmission
7.5CVSS 3.1 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-36020 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-84436Ibm guardium data protection os command injection vulnerabilityIBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated…EPSS 0.68%8.8CVE-2026-84440Ibm guardium data protection os command injection vulnerabilityIBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can …EPSS 0.74%8.1CVE-2026-84842Ibm guardium data protection path traversal vulnerabilityIBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remo…EPSS 0.39%7.2CVE-2026-84422Ibm guardium data protection os command injection vulnerabilityIBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authe…EPSS 0.68%6.7CVE-2025-3473Ibm guardium data protection vulnerabilityIBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by …EPSS 0.14%6.5CVE-2026-8405Ibm guardium data protection information exposure vulnerabilityIBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive …EPSS 0.38%4.9CVE-2026-4917Ibm guardium data protection path traversal vulnerabilityIBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafte…EPSS 0.42%4.9CVE-2026-1274Ibm guardium data protection vulnerabilityIBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2025-36020), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.