CVE-2026-14350: Vulnerabilities exists in IBM Cloud Pak for Data System
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cloud Pak for Data Systemto a version that resolves this vulnerability.Fixed in 11.3.1.2-IF1-WS-ICPDS-NPS-Clients-fp326919Patch fp326919
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is remotely exploitable with low attack complexity and requires no privileges or user interaction. An unauthorized user could inject data into log messages.
What security impact is identified?
The stated impact is limited to integrity of log messages. No confidentiality or availability impact is identified in the supplied severity vector.
Which releases are identified as affected?
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is identified as affected.