CyberRota Analysis
AI-GeneratedIBM Guardium Data Protection 12.2 is susceptible to OS command injection through the Universal Connector plugin's upload feature, allowing a privileged authenticated attacker to execute arbitrary commands with root-level privileges by supplying a malicious filename. This vulnerability poses a significant risk to the integrity and security of the system, making it critical for organizations using this version of Guardium to prioritize remediation efforts. Security teams should assess their environments and apply necessary updates or mitigations to safeguard against potential exploitation.
Original NVD Description
IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.
Related CVEs
Other vulnerabilities affecting the same vendor(s)