Impact
IBM Guardium Data Protection 12.2 contains a flaw that allows a remote attacker to embed special elements in an OS command, leading to arbitrary command execution on the host. This type of vulnerability is categorized as OS Command Injection (CWE-78), enabling the attacker to obtain remote code execution, data exposure, and potentially full system compromise. The flaw is exploitable without authentication or local access as described, meaning a compromised or unauthenticated network interface could be abused.
Affected Systems
The affected product is IBM Guardium Data Protection version 12.2. Backward‑compatible version numbering indicates that all sub‑releases of 12.2 are impacted. No further vendor specifics are provided beyond the product name, and version information is limited to the single release 12.2 in the CPE data.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity impact. The EPSS score is currently unavailable, so there is no published probability data. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in widespread exploitation, but this does not reduce the risk of future attacks. The likely attack vector is over the network, possibly through exposed Guardium Data Protection services that accept untrusted input. Because the flaw allows arbitrary commands, successful exploitation would grant the attacker full control of the protected system. Immediate remediation is strongly recommended.
OpenCVE Enrichment