IBM: rilevato sfruttamento in rete della CVE-2026-85542

Imported from official source

Advisory

Cybersecurity Classified by Officially

IBM: rilevato sfruttamento in rete della CVE-2026-85542

Rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2026-85542 – già sanata dal vendor - che interessa il prodotto IBM Guardium Data Protection. Tale vulnerabilità potrebbe consentire a un utente malintenzionato autenticato di elevare i propri privilegi ed eseguire codice arbitrario sui sistemi interessati.

Nel dettaglio, la vulnerabilità identificata tramite la CVE-2026-85542, di tipo "Arbitrary Code Execution", e con CVSS 3.1 pari a 8.8, già sanata dal vendor, è dovuta ad una gestione non adeguata dei parametri forniti in input dall'utente nella funzionalità di importazione dei bundle GIM (Guardium Installation Manager). Un utente malintenzionato remoto autenticato potrebbe sfruttare tale vulnerabilità per inviare file opportunamente predisposti in grado di influenzare gli argomenti passati al comando di sistema tar ed eseguire codice arbitrario sul sistema interessato.

IBM Security Guardium Data Protection, versione 12.2, in assenza del fix pack SqlGuard_12.0p233

This is an extract. The publication continues at the source.

Read the original at the source: https://www.acn.gov.it/portale/w/ibm-rilevato-sfruttamento-in-rete-della-cve-2026-85542

Officially imported this from Agenzia per la Cybersicurezza Nazionale’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Agenzia per la Cybersicurezza Nazionale — imported from official source
Official source
https://www.acn.gov.it/portale/feedrss/-/journal/rss/20119/723192 RSS
Imported
September 28, 2026 10:30
Versions
1 recorded
Identity
https://www.acn.gov.it/portale/w/ibm-rilevato-sfruttamento-in-rete-della-cve-2026-85542

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.