Impact
A remote authenticated attacker can exploit IBM Guardium Data Protection 12.2 by injecting unsanitized input into web pages, enabling arbitrary code execution on the protected server. This vulnerability is a CWE-79 type weakness that can lead to disclosure of sensitive data, alteration of system state, or denial of service if the attacker runs malicious payloads.
Affected Systems
IBM Guardium Data Protection version 12.2 is affected. Users of the 12.2 release should review the fix pack information listed in the IBM support page for the 12.2.0 release.
Risk and Exploitability
The CVSS score of 9.6 indicates a high severity. External exploit probability is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires an authenticated session to the Guardium web interface, which means only users with valid credentials can upload malicious input and trigger code execution. Once exploited, attacker control over the Guardium server can lead to complete compromise of the protected environment.
OpenCVE Enrichment