Executive brief
IBM DataStage is a data integration and transformation tool that processes data pipelines across enterprise systems. A flaw in the product allows authenticated users to inject arbitrary operating system commands due to improper input validation, enabling complete system compromise including data theft and operational disruption.
Technical details
The vulnerability is an OS command injection (CWE-78) caused by improper neutralization of special elements in user-supplied input to an OS command execution function. An authenticated attacker can craft malicious input that breaks out of the intended command context and execute arbitrary shell commands with the privileges of the DataStage process. No user interaction or special configuration is required beyond authentication. Successful exploitation grants full code execution on the affected system, allowing data exfiltration, lateral movement, and service disruption. IBM has published a security bulletin documenting this and multiple related vulnerabilities affecting DataStage on Cloud Pak for Data 5.4.0.0.
Affected products
- IBM DataStage on Cloud Pak for Data 5.4.0.0
Timeline
- 2026-09-10: disclosed