Impact
IBM Cloud Pak for Data 5.1.2 contains a command injection flaw that allows an authenticated user to execute arbitrary operating‑system commands with elevated privileges. The vulnerability arises from the application failing to properly validate user‑supplied input before it is passed to the operating system. An attacker who can authenticate to the system could run any command, potentially gaining full control over the host, exfiltrating data, or disrupting services.
Affected Systems
The affected product is IBM Cloud Pak for Data version 5.1.2. The vendor has released version 5.2.2 as the minimum supported fix. No other product versions are listed as affected, implying that earlier releases may not contain the flaw and later releases are presumed to be patched.
Risk and Exploitability
A CVSS score of 8.8 marks this as a high‑severity issue. The EPSS score is <1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV, indicating no confirmed exploitation to date. The flaw requires an authenticated user; therefore the attack vector is likely local or remote with valid credentials. Once exploited, the attacker can execute arbitrary commands with elevated privileges, leading to complete compromise of the underlying host.
OpenCVE Enrichment