CVE-2026-84250 — IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component.
Description
IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.
CVSS v3.1 base metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
High
Integrity
A
High
Availability
Related threats
same CWE or vendorCVE-2026-85488 — Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer.
CVE-2026-85488 · 15h ago
CVE-2026-85422 — A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binar…
CVE-2026-85422 · 15h ago
CVE-2026-92861 — The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the applic…
CVE-2026-92861 · 19h ago
CVE-2026-62252 — Homer is open source telecom observability software.
CVE-2026-62252 · 1d ago
CVE-2026-102161 — An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards clie…
CVE-2026-102161 · 2d ago
CVE-2026-61421 — Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization.
CVE-2026-61421 · 2d ago