Impact
IBM Guardium Data Protection 12.2 contains a cross‑site request forgery flaw that allows a remote attacker to submit forged requests from a victim’s browser. The vulnerability falls under CWE‑352 and permits the attacker to bypass configured security restrictions, potentially leading to unauthorized data access or operation execution without proper authentication.
Affected Systems
The flaw affects IBM Guardium Data Protection version 12.2.0 and any 12.2 releases listed in the FixID documentation. Systems running this version on any supported platform are vulnerable.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is considered high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, but the nature of the CSRF flaw means exploitation can occur remotely through standard web traffic. The likely attack vector is a web‑based CSRF attack, where a victim’s authenticated session is manipulated, leading to a high probability of successful compromise if the vulnerability remains unpatched.
OpenCVE Enrichment