Impact
An operating‑system command injection flaw (CWE‑78) exists in the Universal Connector plugin upload feature of IBM Guardium Data Protection 12.2. A privileged authenticated user can supply a malicious filename that is incorporated into a shell command executed by the application, allowing arbitrary root‑level command execution. This directly compromises confidentiality, integrity, and availability of the protected data.
Affected Systems
The vulnerability is limited to IBM Guardium Data Protection version 12.2 running on Linux platforms. The specific entry point is the Universal Connector plugin upload functionality.
Risk and Exploitability
The CVSS score of 7.2 denotes medium‑to‑high severity, while the EPSS score of 1% indicates a very low but non-zero probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker must be a privileged, authenticated user with access to the plugin upload interface; once achieved, the attacker can execute any command with root privileges, presenting a high risk to system security.
OpenCVE Enrichment