IBM DataStage on Cloud Pak for Data Command Injection Vulnerability
Vulnerability
A command injection vulnerability has been identified in IBM DataStage on Cloud Pak for Data, affecting versions 5.1.2 through 5.3.0. This vulnerability allows authenticated users to execute arbitrary commands with normal user privileges. The issue arises from improper validation of user-supplied input in the job subroutine component, which is part of the runtime environment used by DataStage for processing uploaded files.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of commands on the system, potentially allowing for further exploitation or manipulation of the environment.
Remediation
Users are advised to upgrade to version 5.3.1 or later. Instructions for upgrading can be found in the IBM Cloud Pak for Data documentation.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
