Description
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Directory Traversal
Action: Patch
AI Analysis

Impact

IBM Cloud Pak for Data 5.1.2 allows a remote attacker to traverse directories and read arbitrary files on the underlying system. By sending a URL that contains "../" sequences, the application fails to properly validate or sanitize the path component, enabling access to files outside the intended directory. This weakness can lead to disclosure of confidential configuration files, logs, or other sensitive data, and may facilitate further attacks if such files contain credentials or code that could be executed.

Affected Systems

IBM Cloud Pak for Data version 5.1.2 is the affected product. The vendor’s fix is available in version 5.2.2 and later.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate to high impact. An attacker can trigger the flaw by issuing a crafted HTTP request over the network, without requiring additional privileges or user interaction. Although the EPSS score of < 1% indicates a low probability of exploitation and the vulnerability is not listed in the CISA KEV catalog, the ability to read arbitrary files poses a significant confidentiality risk. The attack vector is network-based and the flaw can be exercised by anyone able to reach the vulnerable endpoint, making the exploitation path straightforward.

Generated by OpenCVE AI on September 19, 2026 at 17:50 UTC.

Remediation

Vendor Solution

Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Cloud Pak for Data5.2.2Download 5.2.2 and follow  instructions https://www.ibm.com/docs/en/cloud-paks/cp-data


OpenCVE Recommended Actions

  • Upgrade IBM Cloud Pak for Data to version 5.2.2 or later following IBM’s documented upgrade procedure.
  • Ensure that HTTP endpoints serving files enforce authentication and adhere to least privilege, so that only authorized users can request files.
  • Restrict network exposure of the Cloud Pak for Data management interface by configuring firewall rules or VPN access so that only trusted hosts can reach the endpoint.

Generated by OpenCVE AI on September 19, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Title IBM Cloud Pak for Data is vulnerable to path traversal
First Time appeared Ibm
Ibm cloud Pak For Data
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:cloud_pak_for_data:5.1.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Data
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T14:42:29.768Z

Reserved: 2025-12-15T20:57:21.492Z

Link: CVE-2025-14753

cve-icon Vulnrichment

Updated: 2026-09-22T14:42:22.495Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:02.120

Modified: 2026-09-22T15:17:08.123

Link: CVE-2025-14753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:00:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')