CVE-2026-81537

8.8

IBM · DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data is vulnerable to remote OS command injection, which allows an authenticated attacker to execute arbitrary code on the underlying system.

Executive summary

An authenticated attacker can execute arbitrary code on IBM DataStage on Cloud Pak for Data 5.4.0.0 due to an OS command injection vulnerability.

Vulnerability

This vulnerability is an OS command injection flaw (CWE-78) that occurs when user-supplied input is not properly sanitized before being passed to a system shell. The vulnerability requires a remote attacker to have authenticated access to the system to trigger the injection.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve remote code execution on the host server. Given the CVSS score of 8.8, this poses a significant risk to the confidentiality, integrity, and availability of the entire Cloud Pak for Data environment, potentially leading to total system compromise and unauthorized data access.

Remediation

Immediate Action: Upgrade to DataStage on Cloud Pak for Data 5.4 patch 7 or later as specified in the official IBM security documentation.

Proactive Monitoring: Review system and application access logs for suspicious shell commands or unusual child processes originating from the DataStage application service account.

Compensating Controls: Implement strict network segmentation to limit access to the affected management interfaces and ensure that only authorized personnel can reach the application.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a critical security risk due to the potential for full code execution. Organizations running version 5.4.0.0 should prioritize the application of the vendor-provided patch to 5.4 patch 7 immediately to eliminate the command injection vector.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources