CVE-2026-80379

8.8

IBM · DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, allowing an authenticated remote attacker to execute arbitrary commands on the underlying system.

Executive summary

An authenticated remote attacker can execute arbitrary OS commands on IBM DataStage on Cloud Pak for Data 5.4.0.0, posing a significant risk of full system compromise.

Vulnerability

This vulnerability is an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in input. A remote attacker with authenticated access can leverage this to execute unauthorized commands with the privileges of the application.

Business impact

The CVSS score of 8.8 reflects the high risk of this vulnerability, as it allows for complete loss of confidentiality, integrity, and availability. Successful exploitation grants an attacker the ability to manipulate data, exfiltrate sensitive information, or disrupt critical business operations, potentially leading to severe reputational and operational damage.

Remediation

Immediate Action: Upgrade IBM DataStage on Cloud Pak for Data to version 5.4 patch 7 or later as specified in the vendor security documentation.

Proactive Monitoring: Monitor system logs for unusual command execution patterns or unexpected child processes originating from the DataStage service account.

Compensating Controls: Implement strict network segmentation and apply Web Application Firewall (WAF) rules to filter suspicious input patterns that might attempt to inject OS command syntax.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS severity and the critical nature of the affected software, organizations should prioritize the application of the vendor-provided patch. Administrators must verify their current installation version and apply the 5.4 patch 7 upgrade immediately to prevent potential unauthorized system access and command execution.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources