Impact
IBM Guardium Data Protection 12.2 contains a hardcoded credentials flaw in the hardware_assess/obstore binaries. A low‑privileged authenticated user can extract the product master secrets, enabling an attacker to authenticate to the internal database as a privileged entity and compromise sensitive system data. The vulnerability is a classic insecure credential issue (CWE-798).
Affected Systems
IBM Guardium Data Protection 12.2 running on Linux is affected. The fix is available through IBM Fix Central and is linked in the advisory. No other versions or platforms are listed as impacted in the current data.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity. The EPSS score of <1% indicates a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is local and authenticated; an attacker with low‑privileged credentials must execute the hardware_assess/obstore binaries to recover the hardcoded master secrets and then use those secrets to gain elevated access to the internal database. This local, authenticated path and the requirement for session‑level access make widespread automation unlikely, but the high severity and possible data compromise remain significant risks.
OpenCVE Enrichment