IBM DataStage on Cloud Pak for Data Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in IBM DataStage on Cloud Pak for Data, affecting versions 5.1.2 through 5.3.0. This vulnerability allows authenticated users to execute arbitrary commands with normal user privileges on the system. The issue arises from improper validation of user-supplied input in the user-defined function component, which can be exploited to inject and execute malicious commands.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of commands on the system, potentially allowing for further exploitation or manipulation of the environment.

Remediation

Users are advised to upgrade to version 5.3.1 or later. Instructions for upgrading can be found in the IBM Cloud Pak for Data documentation.

Added: Mar 3, 2026, 9:26 PM
Updated: Mar 3, 2026, 10:02 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
8.1
exploitability
5.2
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.