---
title: Multiple vulnerabilities found in IBM Guardium Data Security Center
url: https://www.dataloco.com/en/multiple-vulnerabilities-found-in-ibm-guardium-data-security-center
published: 2026-09-19T17:20:26+00:00
language: en
section: Security
source: https://www.security-next.com/190443
organizations: IBM, Guardium
publisher: Dataloco
---

# Multiple vulnerabilities found in IBM Guardium Data Security Center

Multiple vulnerabilities have been identified in the data security platform IBM Guardium Data Security Center, including severe vulnerabilities that require immediate security updates. IBM published a security advisory on September 15, 2026, addressing vulnerabilities in components such as Netty, Jackson Databind, and Apache Log4j. The total number of vulnerabilities addressed is reported to be 251 based on the Common Vulnerabilities and Exposures (CVE) system.

The vulnerabilities in Netty include issues leading to DNS cache poisoning, specifically CVE-2026-47691 and CVE-2026-45674. Both vulnerabilities have a Common Vulnerability Scoring System version 3.1 (CVSSv3.1) base score of 10.0, indicating critical severity. These vulnerabilities arise from inadequate validation of DNS responses, which could allow malicious DNS information to be cached.

In addition, vulnerabilities CVE-2026-54513 and CVE-2026-54512 in Jackson Databind allow bypassing of type whitelisting during deserialization, with both having a CVSS base score of 8.1, marking them as high severity. The advisory also details various other vulnerabilities, including HTTP request smuggling, credential leakage, access control bypasses, and denial of service due to resource exhaustion, some of which date back to vulnerabilities identified before 2020.

IBM recommends users update to version 3.8.11 of the IBM Guardium Data Security Center promptly to mitigate these vulnerabilities. The company is urging immediate action from its users to ensure their systems remain secure.
