CVE-2026-80442
9.9IBM · Guardium Data Protection
IBM Guardium Data Protection 12.2 contains an authenticated OS command injection vulnerability within the exportCertificate functionality.
Executive summary
An authenticated OS command injection vulnerability in IBM Guardium Data Protection 12.2 could allow an attacker to execute arbitrary system commands with elevated privileges.
Vulnerability
This vulnerability is an OS command injection flaw (CWE-78) triggered via the exportCertificate functionality. Successful exploitation requires a valid user account with low privileges to inject and execute unauthorized operating system commands.
Business impact
The vulnerability carries a CVSS score of 9.9, reflecting its critical potential for total system compromise. Successful exploitation grants an attacker the ability to execute arbitrary commands, which directly threatens the confidentiality, integrity, and availability of sensitive data managed by Guardium. This could lead to full system takeover, unauthorized access to databases, or the exfiltration of protected enterprise information.
Remediation
Immediate Action: Update IBM Guardium Data Protection to the version provided in the vendor fix: SqlGuard_12.0p233_FixPack.
Proactive Monitoring: Review system and audit logs for unusual command execution patterns or unauthorized access attempts originating from authenticated service accounts.
Compensating Controls: Restrict access to the exportCertificate functionality to only authorized administrative personnel and ensure that the application is running in a network-segmented environment to limit potential lateral movement.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the critical nature of this vulnerability and the potential for full system compromise, administrators must prioritize applying the provided fix pack immediately. Organizations should verify their current version of IBM Guardium Data Protection and ensure that the documented patch is applied to all affected instances to eliminate the risk of unauthorized OS command execution.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section