Executive brief
IBM Guardium Data Protection is a database security appliance that monitors and controls access to databases. A command injection vulnerability in its remotelog_config import CLI command allows highly privileged authenticated users to execute arbitrary shell commands with root-level privileges, potentially compromising the confidentiality, integrity, and availability of protected database systems.
Technical details
The import remotelog_config file CLI command fails to properly neutralize special shell metacharacters in the filename parameter, allowing OS command injection (CWE-78). An authenticated user with high privileges can inject arbitrary shell commands through the filename parameter and achieve root-level code execution. The vulnerability requires valid CLI authentication and high privilege level to exploit.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed