Impact
The vulnerability is a path traversal flaw that permits a remote authenticated attacker to read, write, or delete arbitrary files on the underlying system. The flaw is classified under CWE‑22, indicating improper handling of user‑supplied path components. By exploiting this weakness, an attacker can compromise the confidentiality and integrity of tampering, or execution of malicious code if privileged files are affected.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. IBM recommends upgrading to 5.4 patch 5 or newer to eliminate the flaw.
Risk and Exploitability
The flaw has a CVSS score of 8.1, signifying high severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploits at this time. The attack would require remote authenticated access; once logged in, an attacker can exploit the path traversal to perform arbitrary file operations.
OpenCVE Enrichment