rootpwn

high · CVSS v3 8.1

CVE-2026-82892

IBM Guardium Data Protection 12.2 contains an OS command injection vulnerability. This flaw allows a remote attacker to execute arbitrary co

Overview

IBM Guardium Data Protection 12.2 contains an OS command injection vulnerability. This flaw allows a remote attacker to execute arbitrary commands on the underlying system. It matters because successful exploitation could lead to full system compromise of sensitive database security monitoring infrastructure.

Description

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Impact

This vulnerability impacts the Confidentiality, Integrity, and Availability of the affected IBM Guardium system. Organizations utilizing this product face potential remote code execution by authenticated or unauthenticated attackers, depending on the specific attack vector. Successful exploitation compromises the security monitoring and data protection infrastructure itself.

Remediation

Apply the latest security updates and official patches provided by IBM for Guardium Data Protection 12.2. Restrict network access to the administrative and management interfaces of the Guardium appliance to trusted administrative networks only. Monitor system logs for unusual command execution patterns or anomalous process creation originating from the application.

Risk context

Rated as a high severity vulnerability with a CVSS v3 score of 8.1, indicating a significant risk to enterprise data security environments. Immediate patching is recommended to mitigate potential remote attacks against database security infrastructure.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
high
CVSS v2
7.6
CVSS v3
8.1
CVSS v4
EPSS

cve rce command-injection ibm guardium high-severity database-security

← All CVEs