Impact
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a command injection flaw that allows a remote authenticated attacker to run arbitrary operating‑system commands. The vulnerability stems from improper sanitization of special elements before they are concatenated into OS command strings, matching CWE‑78. When exploited, an attacker can execute any shell command on the host, potentially compromising system integrity, confidentiality, and availability.
Affected Systems
The flaw affects IBM DataStage on Cloud Pak for Data version 5.4.0.0. IBM recommends upgrading to version 5.4 patch 5 or a later release; no other versions or products are indicated as affected.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high‑severity vulnerability. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. Attack requires remote authenticated access to the DataStage service; the attacker must possess a valid user account. Because the command injection can lead to full system compromise, the risk to confidentiality, integrity, and availability is significant, especially when the service runs with elevated privileges.
OpenCVE Enrichment