Impact
IBM Guardium Data Protection version 12.2 allows an attacker who can send specially crafted input to the system to execute arbitrary operating system commands. This flaw, an OS command injection, can lead to full compromise of the underlying host, resulting in loss of confidentiality, integrity, and availability. The vulnerability is identified as CWE‑78 and is limited to code execution without a demonstrated denial‑of‑service impact.
Affected Systems
The affected product is IBM Guardium Data Protection, specifically version 12.2 on Linux platforms. Both the detailed 12.2.0 and the general 12.2 CPE entries indicate that any installation of this version that has not incorporated the listed fix is vulnerable. No other versions are referenced, so the risk is confined to this specific major release.
Risk and Exploitability
The CVSS score of 8.1 classifies the flaw as High severity, indicating that any successful exploitation would have severe consequences. EPSS is not available, so the current exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA KEV, meaning no confirmed public exploits are known. Nevertheless, because the flaw permits remote attackers to run arbitrary OS commands when the vulnerable interface is exposed, the risk is significant and warrants immediate action.
OpenCVE Enrichment