IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the user-defined function component.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7262347 |
|
History
Tue, 03 Mar 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Mar 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the user-defined function component. | |
| Title | DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environment | |
| First Time appeared |
Ibm
Ibm datastage On Cloud Pak For Data |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.1.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.3.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm datastage On Cloud Pak For Data |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-03-03T20:45:55.395Z
Updated: 2026-03-03T21:31:25.924Z
Reserved: 2025-11-25T20:00:32.872Z
Link: CVE-2025-13687
Updated: 2026-03-03T21:31:22.191Z
Status : Awaiting Analysis
Published: 2026-03-03T21:15:56.113
Modified: 2026-03-03T21:52:29.877
Link: CVE-2025-13687
No data.
ReportizFlow