Impact
IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low‑privileged access to the Collector can supply malformed arguments, bypassing argument validation and executing arbitrary commands as root. This flaw allows the attacker to gain full control of the Collector appliance, compromising its confidentiality, integrity, and availability.
Affected Systems
The affected vendor is IBM and the product is Guardium Data Protection, version 12.2 (including sub‑versions 12.2.0). The vulnerability resides in the Collector appliance component where the nmap_wrapper binary is installed.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity condition, and the EPSS score is not available, implying no current exploitation trend. The vulnerability is not listed in the CISA KEV catalog. Attack requires local access and low privileges; once such access is achieved, the attacker can elevate privileges to full root, resulting in complete compromise of the Collector appliance. The overall risk remains significant for environments where the Collector appliance is reachable by local users.
OpenCVE Enrichment