CVE-2026-85542
8.8IBM · Guardium Data Protection
IBM Guardium Data Protection 12.2 contains a command injection vulnerability in the GIM bundle import feature, allowing authenticated attackers to execute arbitrary commands with elevated privileges.
Executive summary
A critical command injection vulnerability in IBM Guardium Data Protection 12.2 is currently being exploited in the wild, posing a severe risk of unauthorized system-level code execution.
Vulnerability
The vulnerability is a command injection flaw (CWE-78) located within the GIM bundle import functionality. An authenticated attacker can supply a malicious bundle that injects arbitrary arguments into the system tar command, leading to command execution with elevated privileges on the Central Manager.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve full system compromise, resulting in the potential exfiltration of sensitive database audit data or the disruption of critical security monitoring services. Given the CVSS score of 8.8 and the confirmation of active exploitation, this flaw presents an immediate and high-level risk to organizational data integrity and compliance posture.
Remediation
Immediate Action: Update IBM Guardium Data Protection to the version specified in the vendor security advisory, specifically applying the fix pack SqlGuard_12.0p233_FixPack.
Proactive Monitoring: Review system logs for unusual GIM bundle import activities or unexpected child processes spawned by the tar utility.
Compensating Controls: Restrict administrative access to the Central Manager and GIM import functions to a strictly defined set of trusted users to minimize the potential attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The active exploitation of this vulnerability necessitates an immediate response from all organizations utilizing the affected software. Security teams should prioritize the deployment of the provided fix pack to eliminate the underlying command injection vector and prevent unauthorized administrative access to the Central Manager.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section