high · CVSS v3 7.2
CVE-2026-84071
IBM Guardium Data Protection 12.2 contains an operating system command injection vulnerability within its Universal Connector plugin upload
Overview
IBM Guardium Data Protection 12.2 contains an operating system command injection vulnerability within its Universal Connector plugin upload functionality. A privileged attacker can exploit this via a maliciously crafted filename to execute arbitrary shell commands. This matter is critical because successful exploitation achieves root-level privileges on the underlying host.
Description
IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.
Impact
A compromise of this nature results in a complete loss of Confidentiality, Integrity, and Availability (CIA) of the affected database security appliance. Because execution occurs with root privileges, the host operating system and all managed database security logs or policies are exposed. Privileged administrators and organizations relying on the appliance for data security and compliance are directly impacted.
Remediation
Apply the official vendor patch or security update provided by IBM for Guardium Data Protection 12.2 as soon as possible. Restrict administrative access and plugin upload capabilities strictly to trusted, vetted personnel to minimize insider or credential-theft risks. Review system logs regularly for anomalous shell execution or unexpected processes originating from the Universal Connector directory.
Risk context
The vulnerability carries a CVSS v3 score of 7.2, categorizing it as high severity. Although EPSS data is not currently available, the requirement for authenticated privileged access reduces immediate exposure, but the catastrophic impact of root-level command execution necessitates prompt remediation.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 8.3
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- —