Impact
IBM Guardium Data Protection 12.2 exposes a missing authorization check within its REST API, allowing an authenticated user to execute requests that should be restricted to privileged roles. The flaw is a classic example of missing access control (CWE‑862). An attacker who can authenticate to the API can therefore elevate privileges by invoking protected endpoints, potentially gaining the ability to alter configuration or view protected data. No further specific administrative actions are claimed in the official description, and the impact is limited to what elevated roles normally possess.
Affected Systems
The vulnerability affects IBM Guardium Data Protection version 12.2, specifically build 12.2.0 as identified by IBM. The vendor fix package, SqlGuard_12.0p233_FixPack, addresses the issue for this release.
Risk and Exploitability
The CVSS score of 8.8 classifies the problem as high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, an attacker with valid credentials can send crafted requests to endpoints that lack proper authorization checks, thereby escalating privileges. The risk is proportional to the exposure space of the REST API within the operating environment.
OpenCVE Enrichment