Impact
The vulnerability is a heap-based buffer overflow in the MongoDB protocol parser of IBM Guardium Data Protection. A specially crafted MongoDB SCRAM username containing an excessive length can corrupt memory, potentially leading to denial of service or arbitrary code execution as reported by IBM.
Affected Systems
IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 are affected. The advisory does not mention later 12.3 releases, so those versions are not known to be vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS is not available, so the exploitation probability is unknown, but the possibility for remote code execution makes the attack highly valuable to adversaries. The vulnerability can be triggered remotely by sending crafted data over the MongoDB protocol to the Guardium engine. No listing in the CISA KEV catalog suggests no known publicly available exploits, yet the high exploit potential warrants urgent action.
OpenCVE Enrichment