Impact
IBM Guardium Data Protection version 12.2 contains an insecure deserialization flaw that allows a remote unauthenticated attacker to execute arbitrary code. The vulnerability is triggered when the system processes untrusted data during normal operation and does not adequately validate or sanitize the serialized payload. The flaw is classified as CWE‑502, which is a vulnerability arising from improper handling of untrusted input during deserialization. Successful exploitation enables direct remote code execution, giving an attacker full control over the host running Guardium.
Affected Systems
The affected product is IBM Guardium Data Protection 12.2 on Linux environments. The specific fix applies to the release identified by the fix ID SqlGuard_12.0p233 in the IBM Fix Central catalog. Earlier releases prior to 12.2 or other products are not listed in the CVE entry, so they are not impacted according to this advisory.
Risk and Exploitability
The CVSS score of 9.8 places this vulnerability in the Critical range, indicating a very high severity. The EPSS score is not available, so current exploitation frequency cannot be quantified. The attack vector is remote and requires no authentication, allowing an attacker to execute arbitrary code and compromise confidentiality, integrity, and availability of the host running Guardium. The vulnerability is not listed in the CISA KEV catalog and, due to the lack of existing mitigations, represents a significant risk. Organizations should treat this issue as a high‑priority security concern.
OpenCVE Enrichment