Executive brief
IBM DataStage on Cloud Pak for Data is a data integration and orchestration platform used to build and manage ETL workflows. A remote authenticated attacker can execute arbitrary OS commands on the server by exploiting improper sanitization of user input, potentially allowing them to compromise the entire system, steal sensitive data, or disrupt critical data processing operations.
Technical details
The vulnerability is an OS command injection (CWE-78) in IBM DataStage on Cloud Pak for Data 5.4.0.0 caused by improper neutralization of special elements used in OS commands. The flaw requires authentication to exploit but does not require user interaction; an attacker can craft a malicious request with shell metacharacters that bypass input validation and execute arbitrary commands with the privileges of the DataStage service. Successful exploitation grants full command execution on the underlying host, enabling data theft, lateral movement, denial of service, or complete system compromise.
Affected products
- IBM DataStage on Cloud Pak for Data 5.4.0.0
Timeline
- 2026-09-10: disclosed