Impact
The vulnerability is a command injection flaw within the SUID-root ssh_config_wrapper component of IBM Guardium Data Protection 12.2. An attacker who has authenticated access with high-privileged rights can supply malicious arguments that the wrapper passes to the operating system shell, leading to arbitrary command execution as the root user. This results in complete compromise of the affected host, giving the attacker full control over the system’s confidentiality, integrity, and availability.
Affected Systems
IBM Guardium Data Protection version 12.2 on Linux platforms is affected. The specific patch applied through IBM’s FixCentral (SqlGuard_12.0p233_FixPack) addresses the issue. No other vendors or product lines are listed.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. Because the flaw requires an authenticated user with elevated privileges and exploits a local SUID-root binary, it is a local vulnerability; the attack vector is thus inferred to be local‑only. The EPSS score is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Nevertheless, any system running the vulnerable component should treat this as a high‑risk weakness that can be exploited by a privileged user to achieve full system takeover.
OpenCVE Enrichment