Impact
The vulnerability in IBM Guardium Data Protection 12.2 allows a remote authenticated attacker to execute arbitrary operating‑system commands by sending specially crafted input that is not properly escaped. The flaw is a command injection (CWE‑78) that can compromise the underlying system, providing full control over the Guardium host. The impact is the ability to execute privileged commands, modify data, or exfiltrate information, potentially leading to full system takeover.
Affected Systems
This issue is present in IBM Guardium Data Protection version 12.2 running on Linux. All installations of that release are affected until the bug fix is applied. The fix is distributed through IBM FixCentral under the product ID SqlGuard_12.0p233_FixPack, which contains the necessary command‑neutralization changes.
Risk and Exploitability
The vulnerability scores a CVSS base of 8.8, placing it in the high severity range. The EPSS score is not available, but the absence of a KEV listing suggests no known public exploitation yet. Attackers would need to be authenticated within Guardium, indicating that securing user credentials and applying the official patch are critical to reduce risk. Once patched, the attack vector would be eliminated.
OpenCVE Enrichment