Impact
IBM Guardium Data Protection version 12.2 contains an improper authorization flaw that allows a remotely authenticated attacker to bypass configured security restrictions. The vulnerability, identified as CWE‑285, could enable the attacker to perform actions beyond their intended privileges, potentially exposing sensitive data or disrupting system operations.
Affected Systems
The affected product is IBM Guardium Data Protection 12.2, including patch level 12.2.0 as referenced by the cpe strings. The release includes a fix (SqlGuard_12.0p233_FixPack) available through IBM Fix Central.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity, and the vulnerability requires authentication; the EPSS score is not available, and the vulnerability is not currently listed in CISA's KEV. Attackers must already have valid credentials but can then extend their access beyond intended limits, making prompt remediation essential.
OpenCVE Enrichment