rootpwn

critical · CVSS v3 8.8

CVE-2026-17102

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to remote command execution via improper sanitization of OS command elements. An a

Overview

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to remote command execution via improper sanitization of OS command elements. An authenticated attacker can run arbitrary commands on the host, potentially compromising the entire system.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Impact

Confidentiality: attacker can read sensitive data. Integrity: attacker can modify or delete data. Availability: attacker can disrupt services. The primary impact is on systems running IBM DataStage on Cloud Pak for Data 5.4.0.0, affecting organizations that rely on this data integration platform.

Remediation

Apply the official IBM security patch for DataStage 5.4.0.0 released on the vendor’s advisory. If patching is delayed, restrict network access to the DataStage service, enforce least privilege for authenticated users, and monitor for anomalous command execution. Consider upgrading to a newer, patched version as soon as possible.

Risk context

Severity is critical with a CVSS v3 score of 8.8, indicating high risk. No EPSS data is available, but the vulnerability allows remote command execution, warranting prompt remediation.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
EPSS

remote command execution IBM DataStage Cloud Pak for Data critical authentication OS command injection

← All CVEs