CVE-2026-82095: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or laterPatch 5.4 patch 5
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
A remote attacker who is authenticated to IBM DataStage on Cloud Pak for Data can exploit it. No user interaction is required.
What impact could successful exploitation have?
Successful exploitation could allow execution of arbitrary code. The supplied severity vector indicates high impacts to confidentiality, integrity, and availability.
Which version is identified as affected?
The advisory data identifies IBM DataStage on Cloud Pak for Data version 5.4.0.0. No other affected or fixed versions are provided.