Impact
IBM Guardium Data Protection version 12.2 contains a command injection flaw in the certificate SMIME recipient deletion command that is exposed through the command‑line interface. An attacker who has authenticated to the system and possesses privileged CLI access can provide specially crafted input to the deletion routine, causing the underlying shell to execute arbitrary commands with root privileges. This vulnerability effectively grants the attacker full control over the host and access to all data managed by Guardium.
Affected Systems
The issue applies to IBM Guardium Data Protection 12.2 running on Linux platforms. IBM is the vendor, and version 12.2 is listed in the vendor’s fix guidance.
Risk and Exploitability
The flaw has a CVSS score of 7.2, indicating high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Because exploitation requires an authenticated privileged CLI user, the attack vector is local or requires proximal access to the system where Guardium is installed. Once those conditions are met, the attacker can run arbitrary OS commands as root, allowing complete takeover of the affected machine and access to Guardium data.
OpenCVE Enrichment