Impact
IBM Guardium Data Protection 12.2 is vulnerable because the ChangeTrackerServlet lacks authentication. This missing guard allows an attacker remote to issue requests that can probe, read, or modify protected data and application configuration, thereby compromising confidentiality and integrity of the protected environment. The weakness is classified as CWE‑306, which indicates a failure to check whether the client is authenticated before performing authorization checks.
Affected Systems
The affected vendor is IBM Guardium Data Protection. The specific version identified is 12.2, which is listed in the vendor's fix pack for the SQLGuard component on Linux platforms.
Risk and Exploitability
The CVSS score of 9.9 marks this issue as critical, but the EPSS score of 0.00352 indicates a very low probability of exploitation. It is not listed in the KEV catalog, suggesting no currently documented public exploitation. The flaw can be exploited remotely via an unauthenticated HTTP request to the vulnerable servlet, requiring no special user privileges or additional access controls to launch the attack.
OpenCVE Enrichment