CVE-2025-13688

Published Mar 3, 2026

Last updated a day ago

Overview

Description
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the wrapped command component.
Source
psirt@us.ibm.com
NVD status
Analyzed
Products
datastage_on_cloud_pak_for_data

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

psirt@us.ibm.com
CWE-78

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.