Impact
IBM Guardium Data Protection 12.2 contains an improper limitation of a pathname to a restricted directory, which can be exploited by a remote authenticated attacker to execute arbitrary code. The weakness is a path traversal flaw (CWE‑22). As a result, an attacker who can authenticate can run code with the privileges of the Guardium service, potentially compromising data confidentiality, integrity, and availability on the host system.
Affected Systems
The vulnerability affects IBM Guardium Data Protection version 12.2 on Linux platforms. The advisory indicates that users running this release should apply the fix provided by IBM. No other versions are listed as affected in the current advisory.
Risk and Exploitability
The severity of the issue is reflected in a CVSS score of 7.2, classifying it as high risk. EPSS data is not available, so the exact likelihood of exploitation cannot be quantified from publicly available data, but the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a remote authenticated session, meaning an attacker must obtain valid credentials to the Guardium interface to perform exploitation. Once authenticated, the attacker can trigger the vulnerability and gain code execution on the host.
OpenCVE Enrichment