Impact
The vulnerability in IBM DataStage on Cloud Pak for Data 5.4.0.0 stems from improper neutralization of special elements used in an operating‑system command construction routine. According to the description, an authenticated user can inject and execute arbitrary commands on the underlying host. The ability to run arbitrary code gives the attacker full control over the server, enabling data exfiltration, system sabotage, and persistence. The weakness is categorized as CWE‑285, Access Control – Improper Authorization.
Affected Systems
The affected product is IBM DataStage on Cloud Pak for Data version 5.4.0.0. Only this specific build is listed as vulnerable. IBM recommends applying patch 7 or any later patch in the 5.4 series to remediate the flaw. The advisory points to the IBM support page for detailed upgrade instructions.
Risk and Exploitability
The CVSS score of 9.9 classifies the flaw as Critical. EPSS is not available, so the likelihood of exploitation is uncertain, and the vulnerability is not yet listed in CISA KEV. Based on the description, the likely attack vector is remote authenticated access to the DataStage service; an attacker must first obtain valid credentials, then issue a command that is passed unsanitized to the operating system. The elevated privileges granted by the authenticator, combined with the lack of input validation, enable an attacker to achieve complete system compromise. The high impact on confidentiality, integrity, and availability warrants immediate action.
OpenCVE Enrichment