Impact
IBM Guardium Data Protection 12.2 contains a path traversal flaw in the Datasource REST component that allows an authenticated remote attacker to delete arbitrary files. This can lead to loss of critical configuration or data, potentially causing application downtime or compromising system integrity. The vulnerability specifically permits file removal beyond intended directories, enabling attackers to disrupt normal operations.
Affected Systems
The vulnerability affects IBM Guardium Data Protection version 12.2. Users running this release should verify their installed version and apply the available fix or upgrade.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and while the EPSS score is not disclosed, the absence of a KEV listing suggests no publicly reported exploits yet. The attack vector is inferred to be remote, requiring authentication and access to the REST API. An attacker who can authenticate to the system may exploit the path traversal to remove files, causing service disruption or integrity loss.
OpenCVE Enrichment