Description
IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.
Published: 2026-09-18
Score: 7.2 High
EPSS: 1.5% Low
KEV: No
Impact: Root-Level Command Execution via OS Command Injection
Action: Immediate Patch
AI Analysis

Impact

An operating‑system command injection flaw (CWE‑78) exists in the Universal Connector plugin upload feature of IBM Guardium Data Protection 12.2. A privileged authenticated user can supply a malicious filename that is incorporated into a shell command executed by the application, allowing arbitrary root‑level command execution. This directly compromises confidentiality, integrity, and availability of the protected data.

Affected Systems

The vulnerability is limited to IBM Guardium Data Protection version 12.2 running on Linux platforms. The specific entry point is the Universal Connector plugin upload functionality.

Risk and Exploitability

The CVSS score of 7.2 denotes medium‑to‑high severity, while the EPSS score of 1% indicates a very low but non-zero probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker must be a privileged, authenticated user with access to the plugin upload interface; once achieved, the attacker can execute any command with root privileges, presenting a high risk to system security.

Generated by OpenCVE AI on September 19, 2026 at 23:17 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM 12.2 fix pack (SqlGuard_12.0p233) that addresses the command‑injection issue.
  • Limit Universal Connector plugin upload permissions so only necessary administrators may perform uploads.
  • If the upload capability is not required, disable or remove it from the system.
  • Monitor upload activity and associated system logs for anomalous behavior.

Generated by OpenCVE AI on September 19, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T03:55:53.803Z

Reserved: 2026-09-01T06:11:11.055Z

Link: CVE-2026-84071

cve-icon Vulnrichment

Updated: 2026-09-18T20:16:41.817Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:26.687

Modified: 2026-10-06T16:26:47.220

Link: CVE-2026-84071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:15:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')