Impact
The vulnerability stems from improper certificate validation in IBM Guardium Data Protection 12.2, allowing remote attackers to bypass security restrictions and potentially gain unauthorized access to protected data and services. The flaw is a certificate validation error identified as CWE‑295, presenting a significant risk to confidentiality and integrity of the protected environment.
Affected Systems
The affected product is IBM Guardium Data Protection version 12.2. Only this release is listed in the advisory, and no other product versions or vendors are mentioned. The vulnerability applies to the Linux platform as indicated by the fix URL.
Risk and Exploitability
The CVSS score of 8.1 reflects high severity, while the EPSS score is not available, indicating that current data does not estimate exploitation probability. The vulnerability is not listed in the CISA KEV catalog, so there is no confirmed exploitation activity. The likely attack vector is remote network, as the description specifies a remote attacker bypassing security restrictions; the attacker would need to present a forged or fraudulent certificate to the Guardium system. Because the flaw involves certificate validation, the attack is feasible without local access and could be automated by scanning tools or malicious clients. The high CVSS score warrants prompt remediation to mitigate potential data exposure and compromise.
OpenCVE Enrichment