Executive brief
IBM DataStage is a data integration and ETL (extract-transform-load) tool within Cloud Pak for Data that processes business data pipelines. A remote authenticated attacker can inject arbitrary OS commands through improper input validation, allowing them to execute code with the privileges of the DataStage service and potentially access, modify, or delete sensitive data or disrupt operations.
Technical details
This vulnerability is an OS command injection flaw (CWE-78) in IBM DataStage on Cloud Pak for Data 5.4.0.0 caused by improper neutralization of special elements in OS commands. The vulnerability requires remote network access and authenticated credentials (PR:L in the CVSS vector). An attacker with valid credentials can inject shell metacharacters or command separators into input fields, causing the application to execute arbitrary commands on the underlying system. The attack has high impact on confidentiality, integrity, and availability. No patch information is currently provided in the advisory.
Affected products
- IBM DataStage 5.4.0.0
Timeline
- 2026-09-10: disclosed