CVE-2026-80442: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.
Other sources
IBM Security Guardium is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack - Upgrade
Upgrade
IBM Security Guardiumto a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Does exploitation require administrator access or user interaction?
The attacker must be authenticated, but the CVSS vector indicates only low privileges are required. No user interaction is required.
Can this be exploited remotely?
The CVSS vector identifies network access as the attack vector, so systems exposing the affected functionality over the network should be assessed.
Which functionality should be prioritized during triage?
Prioritize review of access to the exportCertificate functionality, where the authenticated OS command injection issue is identified.