Impact
IBM Guardium Data Protection 12.1 and 12.2.2 contain a missing authentication check in the edge-controller component. An unauthenticated remote attacker can trigger the execution of arbitrary container images. This yields full control over the managed edge cluster and can compromise confidentiality, integrity, and availability of the protected data.
Affected Systems
The vulnerability affects IBM Guardium Data Protection versions 12.1 and 12.2.2. All installations that include the edge-controller component are impacted. IBM recommends applying the latest IBM Guardium Data Protection Edge patch 12.0p15004 for all affected systems; for older supported releases the general patch 12.0p147 should be applied.
Risk and Exploitability
The CVSS score is 9.8, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which does not reduce its potential impact. The likely attack vector is an unauthenticated remote connection to the edge-controller service, which is reachable over the network.
OpenCVE Enrichment