Impact
IBM Guardium Data Protection 12.2 contains a path traversal flaw in its GIM file‑upload interface. The vulnerability allows an unauthenticated attacker to place arbitrary files on the Collector, which can lead to the execution of malicious code with Collector privileges. The weakness corresponds to CWE-22 (Path Traversal) and could be leveraged to compromise the entire Guardium deployment.
Affected Systems
Products affected are IBM Guardium Data Protection version 12.2.0 and 12.2. The specific fix is available as the SqlGuard_12.0p233 FixPack for the 12.2 release on IBM Linux and other supported platforms.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability presents a high severity risk. The exploitation does not require authentication, indicating that the attack vector is likely via the public or internal web interface that exposes the GIM file‑upload functionality. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the lack of authentication and the ability to write arbitrary files make it a compelling target for attackers.
OpenCVE Enrichment