Executive brief
IBM Guardium Data Protection is an enterprise data security appliance that monitors and protects sensitive databases. A network attacker can send malicious serialized messages to the Change Audit System listener on port 16017 without authentication, causing the appliance to execute arbitrary code and potentially compromise all protected databases.
Technical details
The vulnerability involves unauthenticated insecure deserialization combined with attacker-controlled reflective method dispatch in the CAS listener component. An unauthenticated network attacker can reach TCP port 16017 and submit crafted serialized objects that trigger arbitrary code execution via reflection. No authentication or user interaction is required; the flaw is a direct code injection issue (CWE-94) in the deserialization handler.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed