Executive brief
IBM Guardium Data Protection is a security tool that monitors and protects sensitive databases. An authenticated attacker can execute arbitrary operating system commands with the privileges of the Guardium service, potentially gaining complete control of the protected database environment and accessing all monitored data.
Technical details
OS command injection vulnerability due to improper neutralization of special elements in an OS command allows remote authenticated attackers to execute arbitrary commands. The attack requires authentication and network access. Successful exploitation grants the attacker command execution privileges on the Guardium Data Protection system.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed