critical · CVSS v3 8.8
CVE-2026-17102
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to remote command execution via improper sanitization of OS command elements. An a
Overview
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to remote command execution via improper sanitization of OS command elements. An authenticated attacker can run arbitrary commands on the host, potentially compromising the entire system.
Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Impact
Confidentiality: attacker can read sensitive data. Integrity: attacker can modify or delete data. Availability: attacker can disrupt services. The primary impact is on systems running IBM DataStage on Cloud Pak for Data 5.4.0.0, affecting organizations that rely on this data integration platform.
Remediation
Apply the official IBM security patch for DataStage 5.4.0.0 released on the vendor’s advisory. If patching is delayed, restrict network access to the DataStage service, enforce least privilege for authenticated users, and monitor for anomalous command execution. Consider upgrading to a newer, patched version as soon as possible.
Risk context
Severity is critical with a CVSS v3 score of 8.8, indicating high risk. No EPSS data is available, but the vulnerability allows remote command execution, warranting prompt remediation.
Affected products
- IBM DataStage on Cloud Pak for Data 5.4.0.0
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —