Impact
A remote authenticated attacker can execute arbitrary OS commands by supplying special characters in the PxPeek name property. The vulnerability arises from IBM DataStage not properly neutralizing these characters, allowing an attacker to inject and run arbitrary commands on the underlying operating system. This flaw permits a determined attacker, once authenticated, to compromise system confidentiality, integrity, and availability by introducing malicious commands, potentially escalating privileges or exfiltrating data.
Affected Systems
IBM’s DataStage service deployed within Cloud Pak for Data, version 5.4.0.0, is affected. IBM recommends applying the 5.4 patch 5 update or later, which corrects the input handling for the PxPeek name field. Users of the 5.4.0.0 release should review their deployment to ensure the patch is applied and verify that no additional customizations expose the vulnerable property.
Risk and Exploitability
The vulnerability scores a CVSS of 8.8, indicating a high severity and potential impact. EPSS data is unavailable, suggesting limited real‑world exploitation data, and the flaw is not currently listed in the CISA KEV catalog. Exploitation requires remote authentication to DataStage; an attacker with legitimate credentials can inject command strings into the PxPeek name property and trigger arbitrary OS command execution. The risk is elevated for environments with broad DataStage access or inadequate credential management.
OpenCVE Enrichment