CVE-2025-14754 PUBLISHED

IBM Cloud Pak for Data is vulnerable to OS command injection

Assigner: ibm
Reserved: 15.12.2025 Published: 18.09.2026 Updated: 18.09.2026

IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor IBM
Product Cloud Pak for Data
Versions
  • Version 5.1.2 is affected

Solutions

Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Cloud Pak for Data5.2.2Download 5.2.2 and follow instructions https://www.ibm.com/docs/en/cloud-paks/cp-data

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE