Impact
IBM Guardium Data Protection 12.2 suffers from a command injection flaw in its certificate export CLI functionality (CWE-78). An authenticated user with privileged CLI access can issue arbitrary shell commands, causing them to execute with root privileges. This flaw allows the attacker to tamper with system files, exfiltrate data, or mount further attacks on the host.
Affected Systems
IBM Guardium Data Protection version 12.2 is affected. The fix is available as the SqlGuard_12.0p233_FixPack and can be retrieved through IBM’s Fix Central platform.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.1, indicating high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, so the publicly observed exploitation probability is unknown. Exploitation requires a privileged authenticated CLI user; if such a user exists on the target system, the attacker can immediately gain root access. The lack of a public exploit can reduce the immediate threat level, but the high severity score and local nature of the vulnerability mean that organizations should treat it as a critical risk.
OpenCVE Enrichment