Impact
The vulnerability arises from improper neutralization of user-supplied input when generating web pages, allowing a remote attacker to inject and execute arbitrary code. Because the input is not escaped, the attacker can run code within the application’s context, leading to a remote code execution scenario. The weakness is an example of reflected XSS (CWE-79).
Affected Systems
IBM Guardium Data Protection version 12.2, running on Linux platforms, is affected. Users of this version who expose the web interface to the network are at risk.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS is not available, so the present exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, through the publicly-accessible web interface. No special conditions or user privileges are required as described.
OpenCVE Enrichment