Impact
IBM Guardium Data Protection 12.x is susceptible to a heap‑based buffer overflow in the S‑TAP TrafficTap TDS login reassembly. An unauthenticated remote attacker can craft TDS login fragments that exceed the fixed‑size reassembly buffer, leading to either a denial‑of‑service condition or arbitrary code execution on the affected system. This flaw falls under CWE‑119 and directly undermines the confidentiality or integrity of the protected data.
Affected Systems
The vulnerability applies to IBM Guardium Data Protection versions 12.0, 12.1, 12.2, and 12.3 running on Windows. All these releases are affected by the heap overflow in the S‑TAP TrafficTap service.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score is not available. The flaw is listed outside the CISA KEV catalog. Based on the description, the attack vector is likely via unauthenticated remote network traffic that reaches the S‑TAP TrafficTap interface. The exploit requires an attacker to send specially crafted TDS login fragments, a straightforward task given the lack of authentication or pattern verification in the reassembly routine. Successful exploitation can crash the service or allow arbitrary code execution, representing a significant threat for systems that host Guardium Data Protection.
OpenCVE Enrichment