CVE-2026-17102: DataStage on Cloud Pak for Data has several vulnerabilities
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 7
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated to exploit the vulnerability. The supplied information does not identify any required privilege level beyond authentication.
What impact could successful exploitation have?
Successful exploitation could allow arbitrary command execution on the affected DataStage on Cloud Pak for Data deployment, with high impacts to confidentiality, integrity, and availability.
Which version is identified as affected?
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is identified in the available information.