Impact
The vulnerability stems from improper neutralization of special characters used in operating‑system commands, enabling an attacker who can authenticate to the DataStage server to inject arbitrary commands. The flaw is a classic OS command injection (CWE‑78) that can lead to full compromise of the host system, compromising confidentiality, integrity, and availability of the affected platform.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. The vendor recommends applying IBM’s patch 5 for the 5.4 release line or any newer patch level via the IBM Software Hub documentation. Users running earlier or non‑patched 5.4 releases remain vulnerable.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity, and although no EPSS value is currently disclosed, the absence of a KEV listing does not diminish the risk. Given an authenticated attacker can trigger the flaw, the potential impact extends to unauthorized code execution on the underlying operating system, elevating the threat to a life‑time compromise of the Infrastructure.
OpenCVE Enrichment