IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
IBM encourages customers to update their systems promptly.
For all affected versions, IBM strongly recommends addressing the vulnerabilities now by applying the latest IBM Guardium Data Protection Edge patch 12.0p15004:
https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p15004_Edge&includeSupersedes=0&source=fc
For all affected versions, IBM strongly recommends addressing the vulnerabilities now by applying the latest IBM Guardium Data Protection patch 12.0p147:
https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=All&platform=All&function=fixId&fixids=SqlGuard_12.0p147_FixPack&includeSupersedes=0&source=fc