Executive brief
IBM Guardium Data Protection is a database security appliance that monitors and protects sensitive data. A privileged authenticated attacker can upload a malicious file with a crafted filename to the Universal Connector plugin, allowing them to execute arbitrary commands with root-level privileges on the appliance, potentially compromising the entire database security monitoring infrastructure.
Technical details
This is an OS command injection vulnerability (CWE-78) in the Universal Connector plugin upload functionality. A privileged authenticated attacker can inject shell metacharacters into a filename parameter that is unsafely incorporated into a shell command executed by the application, resulting in arbitrary command execution with root privileges. The attack requires authentication and the user to have privileges to upload plugins.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed