Impact
The vulnerability permits a remote authenticated attacker to bypass security restrictions in IBM Guardium Data Protection 12.2 by exploiting an improper authorization mechanism. This flaw can allow the attacker to gain unauthorized access to protected data or perform privileged actions that the system otherwise prohibits, compromising confidentiality and the integrity of data protection controls.
Affected Systems
The affected system is IBM Guardium Data Protection version 12.2 on Linux. Users running this version of Guardium should verify their build against the fix provided at IBM’s support site.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity risk. EPSS data is not available, but the vulnerability is not listed in the CISA KEV catalog, implying no known public exploits at this time. The attack vector is remote and requires valid user credentials; the attacker must first authenticate to the system and then exploit the deficient authorization logic to elevate privileges or bypass restrictions. The absence of a public exploit does not reduce the criticality, as the flaw can be leveraged by any authenticated user who can reach the Guardium interfaces.
OpenCVE Enrichment