Impact
The vulnerable IBM Guardium Data Protection 12.2 application may divulge sensitive data when a detailed technical error message is returned to a browser. This behavior, tied to CWE‑209, enables an authenticated administrative user to retrieve system‑level information that is not intended for end‑user consumption. The disclosed data could then serve as a foothold for subsequent attacks against Guardium or related infrastructure.
Affected Systems
IBM Guardium Data Protection 12.2 is affected, particularly the 12.2.0 and 12.2 releases as identified by the CPE strings. No other versions are reported.
Risk and Exploitability
The CVSS score of 2.7 reflects low severity; EPSS is not available, and the vulnerability is not listed in the KEV authenticated administrative session and the trigger of a technical error condition in the browser, limiting the attack surface to internal or privileged users. Because the impact is limited to information disclosure and no remote code execution or denial of service is reported, the overall risk to the organization remains modest, though organizations with sensitive data should not ignore early mitigation.
OpenCVE Enrichment