CVE-2026-81937: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelogconfig file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to the confidentiality, integrity, and availability of the affected system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires an authenticated user with high privileges who can use the import remotelog_config file CLI command.
Which input is used to inject commands?
The filename parameter of the import remotelog_config file CLI command is the affected input.
What level of access could successful exploitation provide?
A successful attack could result in arbitrary command execution with root privileges, affecting system confidentiality, integrity, and availability.