Description
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Cloud Pak for Data5.2.2Download 5.2.2 and follow instructions https://www.ibm.com/docs/en/cloud-paks/cp-data
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7287142 |
|
History
Fri, 18 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. | |
| Title | IBM Cloud Pak for Data is vulnerable to OS command injection | |
| First Time appeared |
Ibm
Ibm cloud Pak For Data |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:ibm:cloud_pak_for_data:5.1.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm cloud Pak For Data |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-18T15:20:53.573Z
Reserved: 2025-12-15T21:00:12.154Z
Link: CVE-2025-14754
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
