Impact
The vulnerability is a path traversal flaw that permits a remote authenticated attacker to read, write, or delete arbitrary files on the underlying system. The flaw is classified under CWE-22, indicating improper handling of user‑supplied path components. By exploiting this weakness, an attacker can compromise the confidentiality and integrity of tampering, or execution of malicious code if privileged files are affected.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. IBM recommends upgrading to 5.4 patch 5 or newer to eliminate the flaw.
Risk and Exploitability
The flaw has a high severity CVSS score of 8.1. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploits at this time. An attacker can exploit the path traversal to perform arbitrary file operations.
OpenCVE Enrichment