CVE-2025-14754: IBM Cloud Pak for Data is vulnerable to OS command injection
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
Other sources
IBM Cloud Pak for Data could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.2.2