CVE-2026-82098: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or laterPatch 5.4 patch 5
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is remotely exploitable, but the attacker must first authenticate to DataStage on Cloud Pak for Data. No user interaction is required.
What impact could successful exploitation have?
A successful attacker could execute arbitrary operating-system commands. The supplied severity vector indicates high potential impact to confidentiality, integrity, and availability.
Which version is explicitly identified as affected?
IBM DataStage on Cloud Pak for Data 5.4.0.0 is explicitly identified in the available information.