Impact
The flaw in DataStage 5.4.0.0 originates from improper neutralization of special elements used in an OS command. This fault, a classic OS command injection problem (CWE-78), can be exploited by a remote attacker who has legitimate authentication to execute arbitrary code on the host and gain full control.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is the only affected configuration. Only this build incorporates the vulnerable component; versions patched to 5.4 patch 5 or later address the issue.
Risk and Exploitability
The CVSS score of 8.8 indicates high risk. The attack requires authenticated access, so credential compromise or insider use is the most likely vector. Because the flaw allows remote code execution, it poses a critical risk for systems exposed to the network. It is inferred that no active exploit has been observed.
OpenCVE Enrichment