Executive brief
IBM Guardium Data Protection is a security appliance used to monitor and protect databases. An attacker with local access to the Collector appliance can exploit a flaw in the nmap_wrapper binary to gain root privileges, allowing full control of the device and access to all monitored data.
Technical details
The vulnerability is a local privilege escalation in the SUID-root nmap_wrapper binary due to insufficient argument validation. A low-privileged local attacker can supply crafted arguments to execute arbitrary commands with root privileges. This affects the Guardium Collector appliance component.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed