critical · CVSS v3 8.8 · EPSS 0.00409
CVE-2026-82887
IBM Guardium Data Protection 12.2 contains an OS command injection vulnerability. A remote authenticated attacker can leverage this flaw to
Overview
IBM Guardium Data Protection 12.2 contains an OS command injection vulnerability. A remote authenticated attacker can leverage this flaw to execute arbitrary commands on the underlying system. This poses a significant risk to data security and infrastructure integrity.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Impact
Successful exploitation compromises the confidentiality, integrity, and availability of the affected system by granting unauthorized command execution privileges. Organizations relying on this platform for data security face potential complete system takeover. The vulnerability specifically impacts administrators and security teams managing IBM Guardium environments.
Remediation
Apply the official vendor patches or security updates provided by IBM for Guardium Data Protection 12.2 immediately. Restrict administrative network access to trusted management segments and enforce strict the principle of least privilege for authenticated accounts.
Risk context
Rated as a critical severity vulnerability with a CVSS score of 8.8, indicating severe potential impact. The current EPSS score is 0.00409, reflecting a low immediate exploitation probability in the wild, but the critical severity warrants prompt patching.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- 0.00409