Impact
A path traversal flaw in IBM Guardium Data Protection 12.2 allows a remote authenticated attacker to request files outside the intended directory structure, potentially exposing sensitive system files or configuration data. The weakness is classified as CWE-22, indicating that the software incorrectly validates or normalizes path input, enabling the attacker to read or, depending on the target file, compromise confidentiality. The description does not mention arbitrary code execution, so the primary impact is limited to unauthorized file access.
Affected Systems
IBM Guardium Data Protection version 12.2, deployed on Linux. No other versions are listed as affected in the current advisory.
Risk and Exploitability
The CVSS score of 7.6 places the issue in the high severity range. EPSS data is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is remote, but an authenticated session is required, meaning compromise of valid credentials is a prerequisite. Attackers can exploit the flaw by delivering a crafted request containing traversal sequences to vulnerable endpoints, thereby gaining read access to arbitrary files on the host.
OpenCVE Enrichment