Impact
IBM Guardium Data Protection version 12.2 contains an authenticated operating system command injection flaw in the exportCertificate functionality. The weakness, identified as CWE-78, permits an attacker with valid credentials to run arbitrary system commands, thereby compromising confidentiality, integrity, and availability of the affected system. The ability to execute commands allows full control over the host unless additional mitigations are in place.
Affected Systems
The vulnerability affects IBM Guardium Data Protection 12.2. The only affected version currently identified is 12.2, as documented by IBM’s FixPack release notes.
Risk and Exploitability
The CVSS base score of 9.9 indicates a critical severity. Although the EPSS score is not available, the lack of a KEV listing does not reduce the risk; the flaw requires authenticated access, meaning it can be exploited by any user with administrative privileges. When privileged access is on a network‑exposed instance, the potential for widespread compromise is high. The absence of an EPSS value makes it difficult to gauge current exploitation prevalence, but the critical nature of the flaw mandates immediate attention.
OpenCVE Enrichment