Executive brief
IBM Guardium Data Protection is a database security and monitoring solution used to protect sensitive data in enterprise environments. A local attacker with limited user privileges can exploit improper privilege management to gain elevated system privileges, potentially accessing or modifying sensitive data and system configurations without authorization.
Technical details
The vulnerability exists due to improper privilege management in IBM Guardium Data Protection 12.2, allowing a local authenticated attacker to escalate privileges. The attack requires local access and valid user credentials but no user interaction, resulting in elevated privilege execution. No information on patch availability is specified in the advisory.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed