Executive brief
IBM DataStage, a data integration platform used by enterprises to manage and process data pipelines, contains a command injection vulnerability that allows authenticated users to execute arbitrary operating system commands. An attacker with valid credentials could gain complete control over the DataStage system, potentially exposing sensitive data, modifying data pipelines, or disrupting critical data operations.
Technical details
The vulnerability is an OS command injection (CWE-78) in DataStage on Cloud Pak for Data 5.4.0.0 caused by improper neutralization of special elements in OS commands. The flaw requires prior authentication and network access but no user interaction. A successful exploit allows an authenticated attacker to execute arbitrary commands with the privileges of the DataStage service process.
Affected products
- IBM DataStage on Cloud Pak for Data 5.4.0.0
Timeline
- 2026-09-22: disclosed