Executive brief
IBM Cloud Pak for Data System is a data analytics and management platform used by enterprises to process and govern large datasets. The vulnerability allows an unauthenticated attacker to inject malicious data into system log files by exploiting improper input validation. This could lead to log tampering, making it difficult to detect unauthorized activity and potentially compromising audit trails and compliance reporting.
Technical details
This vulnerability is a log injection flaw (CWE-117) that stems from improper neutralization of special elements when writing user-controlled data to log files. An unauthenticated, network-based attacker can inject arbitrary data into log messages without authentication or user interaction required. The attack affects the integrity of log files, allowing an attacker to forge log entries, hide malicious activity, or inject false information into audit trails. The vulnerability is fixed in IBM Cloud Pak for Data System version 11.3.1.2-IF1 or later.
Affected products
- IBM Cloud Pak for Data System 11.3.0.2 through 11.3.0.2-IF1
Timeline
- 2026-09-04: disclosed