Home

Description

IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

PUBLISHED Reserved 2026-03-26 | Published 2026-04-22 | Updated 2026-04-23 | Assigner ibm




MEDIUM: 4.9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

12.1 (semver)
affected

Credits

benjamin.dixon.vaca8k@statefarm.com, benjamin.dixon.vaca8k@statefarm.com, benjamin.dixon.vaca8k@statefarm.com finder

References

www.ibm.com/support/pages/node/7270422 vendor-advisory patch

cve.org (CVE-2026-4917)

nvd.nist.gov (CVE-2026-4917)

Download JSON