Executive brief
IBM DataStage on Cloud Pak for Data is a data integration and transformation tool used by enterprises to build and manage data pipelines. A remote authenticated attacker can inject and execute arbitrary operating system commands through improper input validation, potentially gaining full system access and compromising sensitive data.
Technical details
OS command injection in DataStage due to improper neutralization of special elements in OS commands (CWE-78). The vulnerability requires prior authentication and network access. An authenticated attacker can execute arbitrary commands with the privileges of the DataStage service process, leading to complete system compromise. IBM has issued patches for this vulnerability.
Affected products
- IBM DataStage on Cloud Pak for Data 5.4.0.0
Timeline
- 2026-09-22: disclosed