Impact
IBM Guardium Data Protection 12.2 contains an input validation flaw that fails to neutralize user-supplied data before embedding it into web page output. This missing sanitization allows a remote authenticated attacker to inject arbitrary JavaScript that executes in the victim’s browser, potentially enabling credential theft, session hijacking, or other actions performed under the compromised account. The weakness aligns with CWE‑79.
Affected Systems
The vulnerability affects IBM Guardium Data Protection version 12.2 running on Linux. All installations of the 12.2 release are impacted until the FixPack SqlGuard_12.0p233 is applied. No other product versions were reported to be affected.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. An EPSS score is not available, so the current probability of exploitation remains unknown. Because the flaw requires authentication, an attacker must first obtain valid Guardium web interface credentials before injecting code, which limits the attack surface. The vulnerability is not listed in the CISA KEV catalog, and no public exploitation evidence is known. If credentials are compromised, the attacker could run arbitrary JavaScript with the privileges of the authenticated user, potentially escalating privileges or spreading the compromise to other systems.
OpenCVE Enrichment