Impact
The vulnerability permits a remote authenticated attacker to execute arbitrary operating‑system commands because the application fails to neutralize special elements in the command string. This leads to remote code execution that can compromise system confidentiality, integrity, or availability.
Affected Systems
The flaw is present in IBM DataStage on Cloud Pak for Data version 5.4.0.0. All installations that have not applied IBM’s patch 7 or later are affected.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high risk level. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of mass exploitation is uncertain, yet the requirement for a remote authenticated session means that internal attackers or compromised accounts pose a significant threat.
OpenCVE Enrichment