Impact
IBM Guardium Data Protection 12.2 contains improper privilege management, identified as CWE-269, that allows a local attacker to gain elevated privileges. This flaw enables unauthorized users to execute privileged actions with system‑level permissions, compromising data integrity, confidentiality, and overall system security.
Affected Systems
IBM Guardium Data Protection version 12.2 on Linux is affected. The fix is available as the SqlGuard_12.0p233_FixPack for this product.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. Exploitation takes place when a local user achieves administrative privileges, potentially allowing data theft or tampering. The EPSS score is not available, so the likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA KEV. However, the high impact and local attack vector mean administrators should prioritize remediation.
OpenCVE Enrichment