Description
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
Published: 2026-09-29
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary command execution with root privileges via command injection in a privileged CLI function
Action: Immediate Patch
AI Analysis

Impact

IBM Guardium Data Protection version 12.2 contains a command injection flaw in the certificate SMIME recipient deletion command that is exposed through the command‑line interface. An attacker who has authenticated to the system and possesses privileged CLI access can provide specially crafted input to the deletion routine, causing the underlying shell to execute arbitrary commands with root privileges. This vulnerability effectively grants the attacker full control over the host and access to all data managed by Guardium.

Affected Systems

The issue applies to IBM Guardium Data Protection 12.2 running on Linux platforms. IBM is the vendor, and version 12.2 is listed in the vendor’s fix guidance.

Risk and Exploitability

The flaw has a CVSS score of 7.2, indicating high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Because exploitation requires an authenticated privileged CLI user, the attack vector is local or requires proximal access to the system where Guardium is installed. Once those conditions are met, the attacker can run arbitrary OS commands as root, allowing complete takeover of the affected machine and access to Guardium data.

Generated by OpenCVE AI on September 29, 2026 at 22:36 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the latest IBM Guardium Data Protection 12.2 fix pack that addresses the command‑injection flaw
  • Limit privileged CLI access to a small group of trusted administrators only
  • Enforce the principle of least privilege on all Guardium accounts and monitor privileged CLI activity for suspicious behavior
  • Implement input validation for all CLI commands to ensure no non‑escaped parameters are executed

Generated by OpenCVE AI on September 29, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-30T03:56:41.683Z

Reserved: 2026-09-01T17:54:27.939Z

Link: CVE-2026-84422

cve-icon Vulnrichment

Updated: 2026-09-29T18:11:50.015Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:17.693

Modified: 2026-09-30T04:18:32.760

Link: CVE-2026-84422

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:45:18Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')