IBMCVE-2025-14754
IBM Cloud Pak for Data: code execution
High8.8CVE-2025-14754 · Published Sep 18, 2026 · updated Sep 22, 2026
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cloud Pak for Data Product | <= 5.1.2 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 18 | IBM Guardium Data Protection: improper authorization | High8.1 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: cross-site request forgery | High8.8 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: command injection | High8.1 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: remote code execution | High7.2 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: privilege escalation | High7.8 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: information disclosure | High7.7 | No fix yet |