Impact
The vulnerability is a missing authentication check (CWE-306) in the LoadBalancerServlet of IBM Guardium Data Protection. An attacker who can reach the servlet can invoke privileged load‑balancer functions without providing credentials, which can compromise the integrity of load‑balancer configurations and impact system availability. This flaw represents a critical authentication bypass, allowing unauthenticated users to perform privileged actions.
Affected Systems
IBM Guardium Data Protection product version 12.2 is affected. No other affected versions are listed.
Risk and Exploitability
The CVSS score of 9.9 classifies this flaw as critical, indicating the potential for severe impact if exploited. While the EPSS score is not available, the lack of a public exploit listing and its absence from the CISA KEV catalog do not diminish the risk, because the flaw permits unauthenticated remote access to privileged operations. The likely attack vector is network‑based access to the vulnerable servlet endpoint, requiring no prior authentication. Given the critical severity and the ability to perform unauthorized actions, the overall risk remains high.
OpenCVE Enrichment