Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Published: 2026-09-22
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in IBM DataStage on Cloud Pak for Data 5.4.0.0 stems from improper neutralization of special elements used in an OS command, giving a remote authenticated attacker the ability to execute arbitrary code. This flaw is an instance of OS Command Injection and can compromise confidentiality, integrity, and availability of the affected system.

Affected Systems

Affected is IBM DataStage on Cloud Pak for Data version 5.4.0.0. Vendor IBM offers a fix by upgrading to version 5.4 patch 7 or newer. No other products or versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploits. The vulnerability can be exploited by a remote authenticated attacker, indicating that attackers with valid user credentials could trigger the command injection. No additional prerequisites beyond authentication are mentioned, so the attack vector is likely via the application layer.

Generated by OpenCVE AI on September 22, 2026 at 22:26 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 7 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Apply the IBM‑provided upgrade instructions to move DataStage on Cloud Pak for Data to version 5.4 patch 7 or later.
  • Ensure that any user‑supplied data incorporated into OS commands is validated or sanitized to prevent injection, addressing the underlying CWE‑77 flaw.
  • Restrict privileged user access and monitor system logs for anomalous command‑execution activity to detect potential exploitation attempts.

Generated by OpenCVE AI on September 22, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

Tue, 22 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Title DataStage on Cloud Pak for Data has several vulnerabilities
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T21:24:17.665Z

Reserved: 2026-07-22T19:58:49.216Z

Link: CVE-2026-16672

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:07.280

Modified: 2026-09-22T22:17:07.280

Link: CVE-2026-16672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:30:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')