rootpwn

high · CVSS v3 7.2

CVE-2026-84071

IBM Guardium Data Protection 12.2 contains an operating system command injection vulnerability within its Universal Connector plugin upload

Overview

IBM Guardium Data Protection 12.2 contains an operating system command injection vulnerability within its Universal Connector plugin upload functionality. A privileged attacker can exploit this via a maliciously crafted filename to execute arbitrary shell commands. This matter is critical because successful exploitation achieves root-level privileges on the underlying host.

Description

IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.

Impact

A compromise of this nature results in a complete loss of Confidentiality, Integrity, and Availability (CIA) of the affected database security appliance. Because execution occurs with root privileges, the host operating system and all managed database security logs or policies are exposed. Privileged administrators and organizations relying on the appliance for data security and compliance are directly impacted.

Remediation

Apply the official vendor patch or security update provided by IBM for Guardium Data Protection 12.2 as soon as possible. Restrict administrative access and plugin upload capabilities strictly to trusted, vetted personnel to minimize insider or credential-theft risks. Review system logs regularly for anomalous shell execution or unexpected processes originating from the Universal Connector directory.

Risk context

The vulnerability carries a CVSS v3 score of 7.2, categorizing it as high severity. Although EPSS data is not currently available, the requirement for authenticated privileged access reduces immediate exposure, but the catastrophic impact of root-level command execution necessitates prompt remediation.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
high
CVSS v2
8.3
CVSS v3
7.2
CVSS v4
EPSS

Command Injection IBM Guardium Universal Connector Privileged Access Root Privilege High Severity

← All CVEs