Impact
IBM Guardium Data Protection 12.2 contains a flaw in how it limits file pathnames, allowing a remote attacker to traverse to arbitrary directories. This path‑traversal weakness can lead to reading sensitive files, deleting files, or executing arbitrary code, with potential loss of confidentiality, integrity and availability. The weakness is classified as CWE‑22.
Affected Systems
The vulnerability affects IBM Guardium Data Protection 12.2, including version 12.2.0. The product runs on Linux and is mentioned in the CPE list for 12.2.*.
Risk and Exploitability
With a CVSS score of 7.5 the flaw is high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, making exploitation likelihood uncertain. The description states that a remote attacker can exploit the flaw, so the attack vector is inferred to be over the network and would require remote access to the Guardium system.
OpenCVE Enrichment