Impact
A remote authenticated attacker can inject special characters into the PxPeek name property of IBM DataStage on Cloud Pak for Data, allowing execution of arbitrary operating‑system commands. The flaw stems from improper neutralization of user input. Successful exploitation compromises confidentiality, integrity, and availability by giving the attacker the ability to run code with the service’s privileges, potentially escalating privileges or exfiltrating data.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is vulnerable. The issue is present in the 5.4 release and is addressed in patch 5. IBM recommends updating to version 5.4 patch 5 or later. The affected product is the DataStage service deployed within the Cloud Pak for Data environment.
Risk and Exploitability
The detected flaw carries a CVSS score of 8.8, classifying it as high severity. The EPSS score is below 1 %, indicating a low probability of observed exploitation. The vulnerability is not yet listed in CISA's KEV catalog. Exploitation requires remote authentication; an attacker with valid credentials can supply a crafted PxPeek name string that broad DataStage access or weak credential controls face a higher risk.
OpenCVE Enrichment