← Vulnerability feed

Vulnerability record · CVE-2026-4917 · published 23 April 2026

CVE-2026-4917: Ibm guardium data protection path traversal vulnerability

Ibm · Guardium Data Protection

IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

4.9 CVSS 3.1 Medium EPSS 0.42% · top 66.1% CWE-22 · Path traversal
4.9CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.ibm.com/support/pages/node/7270422 MitigationVendor Advisory

Track CVE-2026-4917 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-84078Ibm guardium data protection missing authentication for critical function vulnerabilityIBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can acc…EPSS 0.47%9.9CVE-2026-84075Ibm guardium data protection missing authentication for critical function vulnerabilityIBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerSe…EPSS 0.59%9.9CVE-2026-84064Ibm guardium data protection sql injection vulnerabilityIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of spe…EPSS 0.62%9.8CVE-2026-84082Ibm guardium data protection sql injection vulnerabilityIBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements …EPSS 0.67%9.8CVE-2026-82967Ibm guardium data protection missing authentication for critical function vulnerabilityIBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access …EPSS 0.79%9.8CVE-2026-82340Ibm guardium data protection code injection vulnerabilityIBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the…EPSS 0.70%9.8CVE-2026-80441Ibm guardium data protection sql injection vulnerabilityIBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionali…EPSS 0.56%9.8CVE-2026-81657Ibm guardium data protection deserialization of untrusted data vulnerabilityIBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of…EPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2026-4917), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.