Heap-Based Out-of-Bounds Read Vulnerability in IBM Guardium Data Protection
CVE-2026-82334

8.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 October 2026

What is CVE-2026-82334?

IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 are exposed to a heap-based out-of-bounds read vulnerability in the TDS7 LOGIN7 protocol parser. A remote attacker can exploit this issue by sending a specially crafted TDS LOGIN7 packet that includes invalid offset or length values. This can lead to unauthorized information disclosure or potentially a denial of service, affecting the availability and integrity of the affected systems.

Affected Version(s)

Guardium Data Protection 12.0

Guardium Data Protection 12.1

Guardium Data Protection 12.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.