Impact
The vulnerability in IBM DataStage on Cloud Pak for Data 5.4.0.0 stems from improper neutralization of special elements used in an OS command, giving a remote authenticated attacker the ability to execute arbitrary code. This flaw is an instance of OS Command Injection and can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected is IBM DataStage on Cloud Pak for Data version 5.4.0.0. Vendor IBM offers a fix by upgrading to version 5.4 patch 7 or newer. No other products or versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploits. The vulnerability can be exploited by a remote authenticated attacker, indicating that attackers with valid user credentials could trigger the command injection. No additional prerequisites beyond authentication are mentioned, so the attack vector is likely via the application layer.
OpenCVE Enrichment