Description
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Published: 2026-09-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 contains a flaw that allows a remote attacker to embed special elements in an OS command, leading to arbitrary command execution on the host. This type of vulnerability is categorized as OS Command Injection (CWE-78), enabling the attacker to obtain remote code execution, data exposure, and potentially full system compromise. The flaw is exploitable without authentication or local access as described, meaning a compromised or unauthenticated network interface could be abused.

Affected Systems

The affected product is IBM Guardium Data Protection version 12.2. Backward‑compatible version numbering indicates that all sub‑releases of 12.2 are impacted. No further vendor specifics are provided beyond the product name, and version information is limited to the single release 12.2 in the CPE data.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity impact. The EPSS score is currently unavailable, so there is no published probability data. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in widespread exploitation, but this does not reduce the risk of future attacks. The likely attack vector is over the network, possibly through exposed Guardium Data Protection services that accept untrusted input. Because the flaw allows arbitrary commands, successful exploitation would grant the attacker full control of the protected system. Immediate remediation is strongly recommended.

Generated by OpenCVE AI on September 19, 2026 at 11:32 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium Data Protection 12.2 patch supplied at the fix URL to neutralize command injection.
  • Restrict network access to Guardium Data Protection services by firewalling or isolating the host so only trusted administrators can reach vulnerable endpoints.
  • If the patch cannot be applied immediately, enforce strict input validation on any data used in OS commands to prevent special elements from being executed.

Generated by OpenCVE AI on September 19, 2026 at 11:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T03:55:49.363Z

Reserved: 2026-08-31T09:13:34.386Z

Link: CVE-2026-82892

cve-icon Vulnrichment

Updated: 2026-09-19T14:05:27.547Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:25.147

Modified: 2026-10-06T15:38:25.073

Link: CVE-2026-82892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:45:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')