CVE-2026-81550: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or later
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be remotely authenticated and have at least low privileges. No user interaction is required.
Which deployment version is identified as affected?
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is identified as affected in the provided information.
What is the potential impact of successful exploitation?
A successful attacker could execute arbitrary code. The supplied severity vector indicates high impacts to confidentiality, integrity, and availability.