Executive brief
IBM Guardium Data Protection is a database security and monitoring appliance used to protect sensitive data and audit database activity. An authenticated administrator can inject and execute arbitrary operating system commands through the certificate export functionality, potentially gaining complete control of the appliance with root-level privileges and compromising all protected data.
Technical details
An OS command injection vulnerability exists in the exportCertificate CLI functionality, allowing a privileged authenticated user to execute arbitrary commands with root privileges through improper neutralization of special elements in OS command construction. The vulnerability requires authentication and administrative privilege, but can be exploited without user interaction to achieve full system compromise with root-level code execution.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed