Local Information Disclosure in IBM Guardium Data Protection
CVE-2026-87980

3.1LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 October 2026

What is CVE-2026-87980?

IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 are impacted by a vulnerability that allows local attackers to access sensitive information. This security issue arises from the cleartext storage of sensitive data in logs, potentially exposing it to unauthorized individuals. Organizations using these affected versions should review their logging practices and consider applying appropriate mitigations to safeguard sensitive information.

Affected Version(s)

Guardium Data Protection 12.0

Guardium Data Protection 12.1

Guardium Data Protection 12.2

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.