Impact
The vulnerability is caused by improper configuration of the XSLT transformation engine in IBM DataStage on Cloud Pak for Data 5.4.0.0. It allows a remote authenticated attacker to inject and execute arbitrary code on the host. The flaw is a typical injection problem involving user supplied XML content, classified as CWE‑94.
Affected Systems
Affected systems are installations of IBM DataStage on Cloud Pak for Data version 5.4.0.0. IBM recommends upgrading to at least patch 5 of the 5.4 series, which can be obtained through IBM's Software Hub documentation. The update addresses the XSLT configuration issue and eliminates the execution path for malicious transforms.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity potential for confidentiality, integrity, and availability compromise. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit requires the attacker to be authenticated to the system, it is most effective against compromised accounts that can access the XSLT engine. If the authentication mechanisms are strong, exposure is limited; however, once authenticated, the attacker can gain full control over the affected environment.
OpenCVE Enrichment