Impact
IBM DataStage on Cloud Pak for Data version 5.4.0.0 contains an OS command injection flaw that permits a remote authenticated attacker to inject and execute arbitrary commands on the host. The vulnerability stems from improper neutralization of special elements used in an OS command, which enables malicious command segments to be appended to legitimate calls. This flaw can be used to gain full control over the execution environment, allowing the attacker to run any command with the privileges of the authenticated user.
Affected Systems
The issue affects IBM DataStage on Cloud Pak for Data 5.4.0.0 only. Prior releases are not listed as impacted. IBM provides a patch in 5.4 patch 7, which addressing the vulnerability through updated runtime components.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity rating. No EPSS score is available, so the quantified exploitation probability cannot be determined; however, the absence of a KEV listing suggests that public exploitation has not been reported. The attack vector is remote and requires authenticated access within the DataStage environment, implying that compromised or privileged credentials are necessary for exploitation. Because the flaw allows arbitrary command execution, the potential impact includes significant loss of control over the host system, making timely remediation essential.
OpenCVE Enrichment