Sceawere

Vulnerability Detail

CVE-2026-84884UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Guardium Reversible Password Storage

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
IBM
Product
Guardium Data Protection
Attack Type
CWE-256 Plaintext Storage of a Password
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-25T14:17:19.770Z",
  "pubdate": "2026-09-25T14:17:19.770Z",
  "executiveSummary": "IBM Guardium Data Protection 12.2 is susceptible to an information disclosure vulnerability stemming from the use of a reversible encryption mechanism for internal REST service-account credentials.\nThis vulnerability allows an authenticated attacker, who has gained unauthorized access to the underlying storage mechanism or configuration files, to decrypt and recover administrative passwords.\nBy obtaining these credentials, an attacker can generate valid administrative REST access tokens, effectively bypassing secondary authentication controls and gaining full administrative control over the REST API interface.\nThe risk is classified as high due to the exposure of administrative-level service credentials, which significantly undermines the integrity and confidentiality of the Guardium deployment.\nExploitation requires the attacker to possess prior authenticated access to the system, enabling them to locate and extract the weakly protected sensitive data stored in plaintext-equivalent format.",
  "technicalDetails": "The root cause of this vulnerability is the implementation of a reversible cryptographic scheme for the storage of internal REST service-account credentials within IBM Guardium Data Protection 12.2.\nRather than employing salted, non-reversible cryptographic hashes or utilizing a secure hardware security module (HSM) or dedicated vaulting service, the application stores the service account passwords in a state that allows for full recovery of the original plaintext value.\nThe vulnerability resides within the internal credential management module responsible for managing REST API service accounts. Because the decryption logic is embedded within the application binary or accessible via the application's runtime environment, an attacker who has secured access to the filesystem or the internal system configuration can reverse the transformation process to retrieve the stored secrets.\nThe exploitation flow typically follows these steps: 1) An attacker gains initial authenticated access to the system through a lower-privileged account or secondary compromise; 2) The attacker identifies the configuration files or database tables where the REST service-account credentials are cached; 3) Using the identified reversible algorithm, the attacker decrypts the stored blobs to obtain the cleartext password; 4) With the cleartext password, the attacker authenticates against the Guardium REST API as an administrative user; 5) The attacker generates a high-privilege access token, granting them persistent, unauthorized administrative access to the REST interface.\nThis vulnerability effectively grants an attacker the ability to maintain administrative control even if their initial access vector is patched or revoked, as they possess the administrative service account credentials. The impact is a total compromise of the REST API's administrative functionality, potentially allowing for the exfiltration of data, modification of security policies, or disruption of database monitoring services managed by the Guardium platform.\nThe vulnerability is inherent to the storage mechanism used in version 12.2 and does not rely on a specific network exposure, though the REST interface's availability over the network facilitates the final stage of the attack once the credentials are harvested."
}
CVE-2026-84884: IBM Guardium Reversible Password Storage (HIGH Severity, CVSS: 7.5) | Sceawere