IBM DataStage on Cloud Pak for Data Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in IBM DataStage on Cloud Pak for Data, affecting versions 5.1.2 through 5.3.0. This vulnerability allows authenticated users to execute arbitrary commands with normal user privileges. The issue arises from improper validation of user-supplied input in the job subroutine component, which is part of the runtime environment used by DataStage for processing uploaded files.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of commands on the system, potentially allowing for further exploitation or manipulation of the environment.

Remediation

Users are advised to upgrade to version 5.3.1 or later. Instructions for upgrading can be found in the IBM Cloud Pak for Data documentation.

Added: Mar 3, 2026, 9:26 PM
Updated: Mar 3, 2026, 10:02 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.