CVE-2026-80412

8.8

IBM · DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection due to improper escaping of connector property values during OSH script generation.

Executive summary

A remote authenticated attacker can execute arbitrary code on IBM DataStage on Cloud Pak for Data 5.4.0.0 by exploiting improper connector property sanitization.

Vulnerability

This vulnerability is an OS command injection flaw, identified as CWE-78, where an authenticated attacker can manipulate connector property values to execute unauthorized OS commands during OSH script generation.

Business impact

Successful exploitation of this vulnerability allows an authenticated attacker to achieve remote code execution, granting them the ability to compromise the confidentiality, integrity, and availability of the affected system. With a CVSS score of 8.8, this flaw represents a significant threat to data security and operational stability, as it could lead to full system takeover or unauthorized access to sensitive data processed by the DataStage platform.

Remediation

Immediate Action: Upgrade DataStage on Cloud Pak for Data to version 5.4 patch 7 or later as specified in the official IBM support documentation.

Proactive Monitoring: Monitor system logs for unusual command execution patterns or unauthorized modifications to OSH script configurations.

Compensating Controls: Ensure strict access control policies are enforced to limit the number of authenticated users who have permissions to modify connector properties.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high severity of this remote code execution vulnerability, organizations should prioritize the application of the vendor-provided patch. Administrators must verify their current version of DataStage on Cloud Pak for Data and perform the upgrade to version 5.4 patch 7 or later immediately to eliminate the risk of command injection.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources