CVE-2026-81669: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges.
Other sources
IBM Security Guardium is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protection 12.2to a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs access to the Guardium CLI as an authenticated privileged user. The vulnerable input is the alias parameter of the create csr wildcard CLI command.
What level of access could successful exploitation provide?
Successful exploitation can execute arbitrary shell commands with root privileges on the affected system.