Impact
IBM Guardium Data Protection 12.2 contains an improper authorization flaw that may allow a remote attacker to bypass configured security restrictions. The vulnerability enables the attacker to gain privileged or otherwise unauthorized access to protected data and functions, potentially exposing sensitive information or compromising data integrity. The weakness is classified as CWE-285, which reflects inadequate enforcement of access controls.
Affected Systems
The vulnerability affects IBM Guardium Data Protection version 12.2, operating on Linux platforms. Customers using the 12.2 release must apply the IBM-published fix pack that addresses the improper authorization issue.
Risk and Exploitability
With a CVSS score of 8.1, this flaw is considered high severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog, meaning no widespread exploitation has been reported yet. Nonetheless, the flaw is remotely exploitable, requiring only authenticated or potentially unauthenticated access in some configurations, and it could result in privilege escalation and data exposure.
OpenCVE Enrichment