Impact
The vulnerability is a command injection flaw in the import remotelog_config CLI command of IBM Guardium Data Protection 12.2. When a highly privileged authenticated user provides a filename containing shell commands, the system passes the value directly to the shell executable. This flaw, categorized under CWE-78, can allow an attacker to execute arbitrary commands with root privileges, compromising confidentiality, integrity, and availability of the protected data and infrastructure.
Affected Systems
Affected products are IBM Guardium Data Protection version 12.2, specifically the Linux release. The flaw exists in the package referenced by CPE strings indicating 12.2.0 and 12.2. Users running the affected software without the vendor‑supplied fix pack should consider their installations vulnerable until patching.
Risk and Exploitability
The CVSS base score of 7.2 indicates high severity. EPSS is not available, making it unclear how frequently this bug is exploited in practice, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires a highly privileged authenticated user, the attack vector is likely internal or comes from a compromised account. If exploited, an attacker could take full control of the system, execute arbitrary code, and bypass all security controls.
OpenCVE Enrichment