Description
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Published: 2026-09-04
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Log injection
Action: Immediate Patch
AI Analysis

Impact

An unauthorized user can inject content into log files by exploiting an omission of neutralization for special characters. The flaw allows the user to alter the structure or content of log entries, potentially masking malicious actions or creating confusion during forensic analysis. This constitutes a log injection vulnerability (CWE-117) that can affect confidentiality, integrity, and the reliability of monitoring and auditing processes.

Affected Systems

IBM Cloud Pak for Data System version 11.3.0.2 through Interim Fix 001 are affected. The fix is provided in version 11.3.1.2-IF1-WS-ICPDS-NPS-Clients-fp326919.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. Because the EPSS score is not available and the vulnerability is not catalogued in CISA KEV, the known exploitation probability is uncertain. Based on the description, the attack requires an unauthorized user with the ability to influence log data, which likely occurs in a local or web‑application context. Exploitation would enable log tampering but does not grant arbitrary code execution or direct system compromise.

Generated by OpenCVE AI on September 4, 2026 at 20:52 UTC.

Remediation

Vendor Solution

Fix VersionRemediation/FixesIBM Cloud Pak for Data System 11.3.1.2-IF1-WS-ICPDS-NPS-Clients-fp326919 https://www.ibm.com/support/fixcentral/quickorder


OpenCVE Recommended Actions

  • Apply the IBM Cloud Pak for Data System 11.3.1.2-IF1 (or later) update that includes the log neutralization fix.
  • If the update has not yet been deployed, temporarily disable logging of user-supplied data to prevent potential injection until the patch is installed.
  • Review the application’s logging mechanisms to ensure all input data is properly escaped before being written to log files.

Generated by OpenCVE AI on September 4, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Title Vulnerabilities exists in IBM Cloud Pak for Data System
First Time appeared Ibm
Ibm cloud Pak For Data System
Weaknesses CWE-117
CPEs cpe:2.3:a:ibm:cloud_pak_for_data_system:11.3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_data_system:interim:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Data System
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Ibm Cloud Pak For Data System
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T17:26:52.430Z

Reserved: 2026-07-01T16:32:59.757Z

Link: CVE-2026-14350

cve-icon Vulnrichment

Updated: 2026-09-04T17:26:48.443Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T17:16:51.710

Modified: 2026-09-08T14:17:08.940

Link: CVE-2026-14350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T21:45:17Z

Weaknesses
  • CWE-117

    Improper Output Neutralization for Logs