rootpwn

critical · CVSS v3 8.8 · EPSS 0.00409

CVE-2026-82887

IBM Guardium Data Protection 12.2 contains an OS command injection vulnerability. A remote authenticated attacker can leverage this flaw to

Overview

IBM Guardium Data Protection 12.2 contains an OS command injection vulnerability. A remote authenticated attacker can leverage this flaw to execute arbitrary commands on the underlying system. This poses a significant risk to data security and infrastructure integrity.

Description

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Impact

Successful exploitation compromises the confidentiality, integrity, and availability of the affected system by granting unauthorized command execution privileges. Organizations relying on this platform for data security face potential complete system takeover. The vulnerability specifically impacts administrators and security teams managing IBM Guardium environments.

Remediation

Apply the official vendor patches or security updates provided by IBM for Guardium Data Protection 12.2 immediately. Restrict administrative network access to trusted management segments and enforce strict the principle of least privilege for authenticated accounts.

Risk context

Rated as a critical severity vulnerability with a CVSS score of 8.8, indicating severe potential impact. The current EPSS score is 0.00409, reflecting a low immediate exploitation probability in the wild, but the critical severity warrants prompt patching.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
EPSS
0.00409

cve ibm guardium command-injection critical remote-authenticated

← All CVEs