Impact
IBM Guardium Data Protection 12.2 has an improper neutralization of input during web page generation that permits a remote authenticated attacker to execute arbitrary code. The vulnerability is a classic example of injection leading to code execution, classified as CWE‑79, and can compromise the confidentiality, integrity, and availability of the protected data if exploited.
Affected Systems
The affected product is IBM Guardium Data Protection version 12.2, including releases 12.2.0 and later build numbers for the Linux platform, as identified by the provided CPE strings.
Risk and Exploitability
With a CVSS score of 9, this issue is considered critical. The EPSS score is not available, and the vulnerability is not yet listed in CISA KEV, indicating no known active exploitation at time of reporting. The attack requires remote authentication to the Guardium web interface, making it a high‑risk threat for systems that allow unauthenticated or weakly authenticated access to their web console.
OpenCVE Enrichment