Impact
The vulnerability is an OS command injection that can be triggered by a remote authenticated attacker. When exploited, the attacker can execute arbitrary commands on the underlying host, effectively achieving remote code execution, compromising confidentiality, integrity, and availability of the system. The weakness corresponds to CWE-78, which defines unexpected code execution via improper input handling.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. The vendor recommends upgrading to 5.4 patch 5 or a later release. Only this version is listed as vulnerable; no other versions or ranges are mentioned.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. EPSS is not available, so the likelihood of exploitation in the wild is unknown, but the lack of a KEV listing suggests it has not yet been widely exploited. The vulnerability requires a remote authenticated attacker, implying that the attacker must first obtain valid credentials or exploit other component. The OS command injection path would allow the attacker to bypass application controls and run arbitrary commands, which may lead to full system compromise. The absence of public exploits in the CVE description indicates that the issue may still be in a pre-exploit stage.
OpenCVE Enrichment