Description
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.
Published: 2026-09-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Patch Immediately
AI Analysis

Impact

IBM Guardium Data Protection version 12.2 contains an authenticated operating system command injection flaw in the exportCertificate functionality. The weakness, identified as CWE-78, permits an attacker with valid credentials to run arbitrary system commands, thereby compromising confidentiality, integrity, and availability of the affected system. The ability to execute commands allows full control over the host unless additional mitigations are in place.

Affected Systems

The vulnerability affects IBM Guardium Data Protection 12.2. The only affected version currently identified is 12.2, as documented by IBM’s FixPack release notes.

Risk and Exploitability

The CVSS base score of 9.9 indicates a critical severity. Although the EPSS score is not available, the lack of a KEV listing does not reduce the risk; the flaw requires authenticated access, meaning it can be exploited by any user with administrative privileges. When privileged access is on a network‑exposed instance, the potential for widespread compromise is high. The absence of an EPSS value makes it difficult to gauge current exploitation prevalence, but the critical nature of the flaw mandates immediate attention.

Generated by OpenCVE AI on September 19, 2026 at 11:18 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM FixPack for Guardium Data Protection 12.2 (SqlGuard_12.0p233) available through IBM Fix Central.
  • Restrict access to the exportCertificate API by ensuring that only authorized privileged users can invoke it and that it is not exposed to unauthenticated or external traffic.
  • Monitor system logs for suspicious command execution activity and review user permissions for least‑privilege compliance.

Generated by OpenCVE AI on September 19, 2026 at 11:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:40.099Z

Reserved: 2026-08-26T11:21:58.660Z

Link: CVE-2026-80442

cve-icon Vulnrichment

Updated: 2026-09-19T14:07:11.072Z

cve-icon NVD

Status : Received

Published: 2026-09-18T20:17:23.343

Modified: 2026-09-19T15:17:02.547

Link: CVE-2026-80442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T11:30:06Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')