Impact
IBM Guardium Data Protection 12.2 suffers from a command injection vulnerability in its SNMP alert notification functionality. An authenticated attacker who has permission to modify policy alert text can cause arbitrary data supplied in that text to be executed as operating system commands by the SNMP alerter service, which runs with root privileges. This allows the attacker to run any command with the highest privileges on the affected host, effectively providing full control over the system.
Affected Systems
The vulnerability affects IBM Guardium Data Protection version 12.2 running on Linux platforms. The affected component is the SNMP alerter service that processes user‑controlled alert text. Only installations of version 12.2 are listed as vulnerable; earlier or later releases are not currently referenced as impacted.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity vulnerability, and while an EPSS score is not available, the lack of KEV listing suggests no active exploits are known. However, because the flaw requires authenticated access and the SNMP alerter runs as root, once an attacker can influence policy alert text they can execute arbitrary commands. The likely attack vector would be through the application interface or other management protocols that allow the creation or modification of alert text. Given the potential for complete system compromise, the risk remains significant until remediation is applied.
OpenCVE Enrichment