Description
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
Published: 2026-09-29
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution with Root Privileges
Action: Immediate Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 suffers from a command injection vulnerability in its SNMP alert notification functionality. An authenticated attacker who has permission to modify policy alert text can cause arbitrary data supplied in that text to be executed as operating system commands by the SNMP alerter service, which runs with root privileges. This allows the attacker to run any command with the highest privileges on the affected host, effectively providing full control over the system.

Affected Systems

The vulnerability affects IBM Guardium Data Protection version 12.2 running on Linux platforms. The affected component is the SNMP alerter service that processes user‑controlled alert text. Only installations of version 12.2 are listed as vulnerable; earlier or later releases are not currently referenced as impacted.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high severity vulnerability, and while an EPSS score is not available, the lack of KEV listing suggests no active exploits are known. However, because the flaw requires authenticated access and the SNMP alerter runs as root, once an attacker can influence policy alert text they can execute arbitrary commands. The likely attack vector would be through the application interface or other management protocols that allow the creation or modification of alert text. Given the potential for complete system compromise, the risk remains significant until remediation is applied.

Generated by OpenCVE AI on September 29, 2026 at 22:37 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Fix Pack for Guardium Data Protection 12.2 that addresses the SNMP command injection (referenced in the IBM FixCentral link).
  • If the patch cannot be applied immediately, disable SNMP alert notifications or restrict SNMP access so the alerter service cannot process user‑controlled alert text.
  • Enforce strict input validation on policy alert text fields to prevent execution of arbitrary commands, following mitigation guidance for OS command injection (CWE‑78).
  • Restrict user privileges to ensure only trusted administrators can modify alert policies, limiting the attack surface for authenticated exploitation.

Generated by OpenCVE AI on September 29, 2026 at 22:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-30T03:56:47.369Z

Reserved: 2026-09-01T19:28:01.914Z

Link: CVE-2026-84440

cve-icon Vulnrichment

Updated: 2026-09-29T18:12:26.479Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:17.953

Modified: 2026-09-30T04:18:33.167

Link: CVE-2026-84440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T01:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')