CVE-2025-13689 PUBLISHED

DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environment

Assigner: ibm
Reserved: 25.11.2025 Published: 17.02.2026 Updated: 17.02.2026

IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to unrestricted file uploads.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor IBM
Product DataStage on Cloud Pak
Versions Default: unaffected
  • affected from 5.1.2 to 5.3.0 (incl.)

Solutions

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data.

Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.1.2-5.3.0 Upgrade to version 5.3.1 and beyond. https://www.ibm.com/docs/en/software-hub/5.1.x

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE