CVE-2026-16672: DataStage on Cloud Pak for Data has several vulnerabilities
IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Patch patch 7
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker who is authenticated to IBM DataStage on Cloud Pak for Data could exploit the command-neutralization flaw. The provided data indicates low privileges are required and no user interaction is needed.
What is the potential impact of successful exploitation?
Successful exploitation could allow execution of arbitrary code. The listed CVSS vector indicates high impact to confidentiality, integrity, and availability.
Which version is identified as affected?
The provided information specifically identifies IBM DataStage on Cloud Pak for Data version 5.4.0.0.