2026-09-22 21:25CVE-2026-17102ibm
PUBLISHED5.2ApplicationCWE-78

DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Problem type

Affected products

IBM

DataStage on Cloud Pak for Data

5.4.0.0 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-17102
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-17102",
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "dateUpdated": "2026-09-22T21:25:53.760Z",
    "dateReserved": "2026-07-24T15:15:21.195Z",
    "datePublished": "2026-09-22T21:25:53.760Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm",
        "dateUpdated": "2026-09-22T21:25:53.760Z"
      },
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "descriptions": [
        {
          "lang": "en",
          "value": "IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "IBM",
          "product": "DataStage on Cloud Pak for Data",
          "cpes": [
            "cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*"
          ],
          "versions": [
            {
              "version": "5.4.0.0",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
              "cweId": "CWE-78",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7288649",
          "tags": [
            "vendor-advisory",
            "patch"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH"
          }
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data.\n\nProduct(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0\n\nUpgrade to 5.4 patch 7 or later by following these  instructions https://www.ibm.com/docs/en/software-hub/5.4.x .",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<div><p><strong>IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data.</strong></p><div><table><tbody><tr><td>Product(s)</td><td>Version(s) number and/or range </td><td>Remediation/Fix/Instructions</td></tr><tr><td>DataStage on Cloud Pak for Data</td><td>5.4.0.0</td><td><p>Upgrade to 5.4 patch 7 or later by following these <a href=\"https://www.ibm.com/docs/en/software-hub/5.4.x?topic=overview-available-patches-software-hub-version-540\" rel=\"nofollow\">instructions</a>.</p></td></tr></tbody></table></div><p></p></div>"
            }
          ]
        }
      ]
    }
  }
}