Impact
A heap‑based out‑of‑bounds read vulnerability exists in the TDS7 LOGIN7 protocol parser of IBM Guardium Data Protection. The flaw allows a remote attacker to send a specially crafted LOGIN7 packet with invalid offset or length values, causing the application to read beyond intended bounds. This can expose sensitive data from memory or cause a denial‑of‑service by crashing the Guardium process, potentially disrupting secure data monitoring.
Affected Systems
The vulnerability affects IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 running on Windows. It is present in the Windows S‑TAP component and can be mitigated by applying the latest Guardium_12.x.p101_r120203346_S‑TAP_Windows patch, which is available from IBM Fix Central.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity and the lack of an EPSS score means that exploitation probability is currently unknown, but the vulnerability is not listed in the CISA KEV catalog. Because the flaw is exercised by a remote packet over the TDS protocol, an attacker only needs network access to the Guardium server; no local privilege is required. Successful exploitation could lead to data leakage or service interruption, making immediate remediation critical.
OpenCVE Enrichment