Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM encourages customers to update their systems promptly. ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7288040 |
|
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges. | |
| Title | IBM Guardium Data Protection is affected by multiple vulnerabilities. | |
| First Time appeared |
Ibm
Ibm guardium Data Protection |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm guardium Data Protection |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-18T19:28:26.737Z
Reserved: 2026-08-27T10:44:15.809Z
Link: CVE-2026-81669
No data.
Status : Received
Published: 2026-09-18T20:17:24.127
Modified: 2026-09-18T20:17:24.127
Link: CVE-2026-81669
No data.
OpenCVE Enrichment
No data.
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')