Impact
This vulnerability arises from an insecure deserialization flaw combined with attacker‑controlled reflective method dispatch in IBM Guardium Data Protection’s Change Audit System listener. An attacker can supply crafted serialized messages over the network, causing the appliance to execute arbitrary code. The weakness is categorized as CWE-94 and can lead to total compromise of the Guardium appliance, including data access, tampering and service disruption.
Affected Systems
IBM Guardium Data Protection version 12.2 on platforms that expose TCP port 16017 is affected. The fix is available through IBM FixCentral for the 12.2 release. No other versions are listed as vulnerable in the current data.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. While EPSS data is not available, the vulnerability remains unlisted in the CISA KEV catalog. An attacker with network access to port 16017 could exploit the flaw without prior authentication, making the attack surface open to any host that can reach the appliance.
OpenCVE Enrichment