Executive brief
IBM DataStage, a data integration and ETL tool on Cloud Pak for Data, contains a command injection vulnerability that allows authenticated users to execute arbitrary operating system commands. An attacker with valid credentials could gain complete control over the system, leading to data theft, system compromise, or service disruption.
Technical details
OS command injection via improper neutralization of special elements in user-supplied input to an OS command execution context. The vulnerability requires valid authentication and network access; no user interaction needed. An authenticated attacker can execute arbitrary commands with the privileges of the DataStage process, achieving remote code execution with impact to confidentiality, integrity, and availability.
Affected products
- IBM DataStage on Cloud Pak for Data 5.4.0.0
Timeline
- 2026-09-22: disclosed