Executive brief
IBM Guardium Data Protection is a database security appliance that monitors and protects sensitive data. A privileged administrator using the CLI can inject arbitrary shell commands through the certificate signing request feature, gaining complete system control with root privileges on the appliance.
Technical details
Command injection vulnerability in the "create csr wildcard" CLI command allows authenticated privileged users to inject arbitrary shell commands via the alias input parameter. The vulnerability results in command execution with root privileges on the affected appliance. This is a CWE-78 (OS Command Injection) flaw exploitable only by authenticated users with CLI access.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed