CVE-2026-84278: IBM Guardium Data Protection Command Injection
IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root sshconfigwrapper component. An authenticated high-privileged user can inject arbitrary commands through attacker-controlled arguments, resulting in command execution with root privileges.
Other sources
IBM Security Guardium Data Protection is affected by a command injection vulnerability in the SUID-root sshconfigwrapper component. An authenticated high-privileged user can inject arbitrary commands through attacker-controlled arguments, resulting in command execution with root privileges.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Exploitation requires an authenticated, high-privileged user of IBM Guardium Data Protection. The vulnerable component is the SUID-root ssh_config_wrapper.
What level of access can successful exploitation provide?
An attacker who can inject commands through attacker-controlled arguments can execute arbitrary commands with root privileges.