Executive brief
IBM DataStage, a data integration and transformation platform, contains a command injection vulnerability that allows authenticated users to execute arbitrary operating system commands. An attacker with valid credentials could gain full system access, leading to data theft, system compromise, or operational disruption.
Technical details
The vulnerability stems from improper neutralization of special elements in OS command construction (CWE-78), allowing authenticated remote attackers to inject and execute arbitrary commands. The attack requires valid authentication credentials but no user interaction. Successful exploitation grants the attacker code execution with the privileges of the DataStage service process.
Affected products
- IBM DataStage on Cloud Pak for Data 5.4.0.0
Timeline
- 2026-09-22: disclosed