Impact
IBM Guardium Data Protection 12.2 includes an input validation flaw that allows a remote authenticated attacker to inject unneutralized data into web pages. The flaw can be exploited to execute arbitrary code on the protected system. The vulnerability is categorized as a Cross‑Site Scripting (CWE‑79) weakness that directly leads to remote code execution when affected users interact with the vulnerable web interface.
Affected Systems
Vendors and product affected are IBM Guardium Data Protection, specifically version 12.2 (including sub‑version 12.2.0) running on Linux platforms. The fix is available as the IBM Guardium Data Protection 12.2 FixPack 12.0p233.
Risk and Exploitability
The CVSS score of 8.9 classifies this as a high‑severity vulnerability. The EPSS score is not reported, but the lack of a KEV listing suggests that exploitation is not yet widespread. Because the flaw requires authenticated access, the attack surface is limited to users with legitimate login credentials to the Guardium web interface. Once compromised, an attacker can gain complete control over the protected data environment.
OpenCVE Enrichment