Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability in IBM Guardium Data Protection 12.2 allows a remote authenticated attacker to execute arbitrary operating‑system commands by sending specially crafted input that is not properly escaped. The flaw is a command injection (CWE‑78) that can compromise the underlying system, providing full control over the Guardium host. The impact is the ability to execute privileged commands, modify data, or exfiltrate information, potentially leading to full system takeover.

Affected Systems

This issue is present in IBM Guardium Data Protection version 12.2 running on Linux. All installations of that release are affected until the bug fix is applied. The fix is distributed through IBM FixCentral under the product ID SqlGuard_12.0p233_FixPack, which contains the necessary command‑neutralization changes.

Risk and Exploitability

The vulnerability scores a CVSS base of 8.8, placing it in the high severity range. The EPSS score is not available, but the absence of a KEV listing suggests no known public exploitation yet. Attackers would need to be authenticated within Guardium, indicating that securing user credentials and applying the official patch are critical to reduce risk. Once patched, the attack vector would be eliminated.

Generated by OpenCVE AI on September 19, 2026 at 11:54 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the official IBM Guardium Data Protection 12.2 patch (SqlGuard_12.0p233_FixPack) available from IBM FixCentral.
  • Restrict Guardium user accounts to only those necessary for operation, following the principle of least privilege, to limit potential damage from accidental or malicious input.
  • Conduct a post‑patch validation to ensure command inputs are correctly sanitized and that no execution paths remain that can be exploited.

Generated by OpenCVE AI on September 19, 2026 at 11:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T03:55:48.651Z

Reserved: 2026-08-31T09:05:00.865Z

Link: CVE-2026-82887

cve-icon Vulnrichment

Updated: 2026-09-19T14:05:39.678Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:24.893

Modified: 2026-10-06T15:37:54.800

Link: CVE-2026-82887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:45:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')