AI description
CVE-2026-81657 is a security vulnerability identified in IBM Guardium Data Protection version 12.2. This flaw stems from the improper handling of serialized objects, specifically the deserialization of untrusted data. The vulnerability allows a remote, unauthenticated attacker to execute arbitrary code on the affected system. This is achieved by injecting maliciously crafted input that triggers unsafe object reconstruction within the system's memory space, bypassing standard authentication mechanisms. The issue aligns with Common Weakness Enumeration (CWE) identifier CWE-502, which pertains to the deserialization of untrusted data.
- Description
- IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
- Source
- psirt@us.ibm.com
- NVD status
- Received
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@us.ibm.com
- CWE-502
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
10