CVE-2026-84278High· 7.2▾ TwilightIBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper component. An authenticated high-privileged user can inject arbitrary commands through attacker-controlled arguments, …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper component. An authenticated high-privileged user can inject arbitrary commands through attacker-controlled arguments, resulting in command execution with root privileges.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-32751High· 7.5Gradle is a build tool with a focus on build automation
CVE-2022-37912High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37897Critical· 9.8There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211)
CVE-2025-11490Medium· 6.3A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13
CVE-2025-11491Medium· 6.3A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13
CVE-2025-11407Medium· 6.3A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1