Executive brief
IBM Guardium Data Protection is a security tool that monitors and protects database access for enterprises. A vulnerability in version 12.2 allows a remote attacker to execute arbitrary operating system commands with elevated privileges, potentially leading to full system compromise and access to sensitive database information.
Technical details
The vulnerability is an OS command injection flaw (CWE-78) in IBM Guardium Data Protection 12.2 caused by improper neutralization of special elements used in OS commands. This likely affects multiple components as indicated by the advisory (SNMP alerter, ssh_config_wrapper). An authenticated attacker can inject arbitrary commands that execute with root privileges, gaining complete control of the affected system.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed