Impact
IBM Guardium Data Protection 12.2 contains an improper privilege‑management flaw that allows a local attacker to elevate their privileges to that of the system or a higher‑privileged user, potentially enabling complete takeover of the protected environment. The vulnerability is a classic privilege escalation weakness (CWE‑269). An attacker who can run code locally on the Guardium platform can exploit the flaw without authentication, leading to full system control.
Affected Systems
The flaw impacts IBM Guardium Data Protection version 12.2 deployed on Linux hosts. Users running the 12.2 release without the patch are at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability. Because the attack vector is local, the risk is confined to hosts that an attacker can access directly, but such access may be easier in shared or compromised environments. The EPSS score is not reported, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. Nonetheless, the potential for complete system compromise warrants urgent remediation.
OpenCVE Enrichment