CyberRota Analysis
AI-GeneratedIBM Guardium Data Protection 12.2 is susceptible to a command injection vulnerability that allows highly privileged authenticated users to execute arbitrary shell commands via the filename parameter in the import remotelog_config CLI command. This could lead to severe impacts on the confidentiality, integrity, and availability of the system, making it critical for organizations using this version of Guardium to prioritize remediation efforts. Security teams should focus on monitoring and patching this vulnerability to mitigate potential exploitation risks.
Original NVD Description
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to the confidentiality, integrity, and availability of the affected system.
Related CVEs
Other vulnerabilities affecting the same vendor(s)