Impact
IBM Guardium Data Protection 12.2 contains an authentication bypass flaw that lets an unauthenticated remote attacker circumvent the system’s IP‑based access controls and reach the Guardium management console. Once accessed, the attacker could view or alter configuration settings, potentially exposing sensitive data or altering security controls. The flaw is rated CVSS 9.8, indicating a high‑severity risk of unauthorized privileged access.
Affected Systems
The vulnerability affects IBM Guardium Data Protection version 12.2. A security fix is available for this release and can be applied via the IBM Fix Central portal for Linux platforms.
Risk and Exploitability
The attack path requires the adversary to reach the Guardium management interface over the network, but IP‑based restrictions are nullified by the flaw, so any host that can reach the interface may exploit it. No EPSS score is published, but the CVSS score shows a severe risk. The vulnerability is not listed in the CISA KEV catalog, and no known public exploits are documented. Inferred from the description that the vector is remote, but detailed exploitation steps are not specified.
OpenCVE Enrichment