Impact
The vulnerability is a Bypass Business Logic flaw in the access management control panel of IBM Guardium Data Protection. It can allow an attacker to gain elevated privileges or access sensitive data that should otherwise be restricted. This weakness corresponds to CWE-840.
Affected Systems
IBM Guardium Data Protection products, specifically versions 12.0, 12.1, and 12.2 running on Linux-based platforms, are affected.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate potential impact, while the EPSS score of less than 1 % shows a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the administrative web interface, requiring an authenticated session or an insider with limited privileges to exploit the control panel. Attackers could elevate privileges or bypass permissions, potentially leading to unauthorized access to protected data.
OpenCVE Enrichment