Impact
IBM Guardium Data Protection 12.2 contains a hard‑coded recovery key within the pkcrypto passkey component and weak cryptographic protections. The vulnerability allows a local attacker to retrieve this key, recover the system root password, and obtain root privileges, thereby compromising the entire system’s confidentiality, integrity, and availability.
Affected Systems
The affected product is IBM Guardium Data Protection version 12.2. The fix is released as the SqlGuard_12.0p233_FixPack upgrade for 12.2.0 and later.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity. EPSS information is not available and the vulnerability is not listed under CISA KEV. Because the attack requires local access, the principal vector is local exploitation; a local attacker can leverage the hard‑coded key to elevate privileges. Based on the absence of documented public exploits, no public exploit is currently recorded, but the potential for local privilege escalation remains significant.
OpenCVE Enrichment