Impact
The vulnerability is an OS command injection flaw that allows a remote authenticated attacker to run arbitrary commands on the host system. This occurs due to improper validation of input used in system calls, classified as CWE-78. With valid credentials, an attacker can inject malicious commands and gain full control, compromising data confidentiality, integrity, and availability.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected by this weakness. No other product versions are currently listed as vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity exploit that permits Remote Code Execution. The EPSS score is not available, so the current likelihood of exploitation is unknown, but the absence of a KEV listing does not mitigate the inherent risk. The flaw requires remote authenticated access; an attacker who can obtain or trick valid credentials can use the injection point to execute arbitrary commands, potentially achieving full system compromise. Prompt remediation, such as upgrading to the recommended patch, is essential to mitigate this threat.
OpenCVE Enrichment