Impact
IBM Guardium Data Protection 12.2 is vulnerable to a command injection flaw in the create csr wildcard CLI command; an authenticated privileged user can inject arbitrary shell commands through the alias input, allowing execution with root privileges. The vulnerability directly compromises confidentiality, integrity, and availability by enabling an attacker to run any code on the host system.
Affected Systems
IBM Guardium Data Protection 12.2 on Linux environments is affected, with the fix available as IBM QuickOrder SQLGuard_12.0p233_FixPack for release 12.2.
Risk and Exploitability
The CVSS score of 7.2 classifies the issue as high severity, and the EPSS score is not available but the lack of listing in CISA KEV does not reduce the risk profile. The vulnerability requires authentication with privileges to the CLI, which limits the attack surface somewhat; however, once accessed, the attacker can execute arbitrary commands and compromise the entire system. Scaling can be limited to systems that expose the vulnerable CLI path, but all affected installations are at risk if an authenticated privileged user is compromised.
OpenCVE Enrichment