Impact
This vulnerability exists in IBM Guardium Data Protection 12.2.2, where an unauthenticated remote attacker can target the edge‑controller’s gRPC service. By sending malformed task data, the attacker exploits an unchecked type assertion that leads the edge‑controller process to crash. The resulting denial of service removes the availability of the protected data environment until the process is restarted or the system rebooted.
Affected Systems
Affected products are IBM Guardium Data Protection version 12.2.2, operating on Linux platforms. Version 12.2.3 contains the fix for the denial‑of‑service issue and is available through IBM’s FixCentral or product upgrade channels.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating a high severity rating. The EPSS score is not provided, and the issue is not listed in the CISA KEV catalog. Attackers only need unauthenticated network access to the privileged edge‑controller gRPC endpoint; no local privileges are required. Since the exploit can be performed remotely, it poses a significant risk of unplanned service downtime in environments that rely on Guardium for data protection.
OpenCVE Enrichment