Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.
Published: 2026-09-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Manipulation
Action: Patch Now
AI Analysis

Impact

The vulnerability is a path traversal flaw that permits a remote authenticated attacker to read, write, or delete arbitrary files on the underlying system. The flaw is classified under CWE-22, indicating improper handling of user‑supplied path components. By exploiting this weakness, an attacker can compromise the confidentiality and integrity of tampering, or execution of malicious code if privileged files are affected.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. IBM recommends upgrading to 5.4 patch 5 or newer to eliminate the flaw.

Risk and Exploitability

The flaw has a high severity CVSS score of 8.1. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploits at this time. An attacker can exploit the path traversal to perform arbitrary file operations.

Generated by OpenCVE AI on September 20, 2026 at 23:00 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Apply IBM DataStage on Cloud Pak for Data 5.4 patch 5 or later
  • Restrict user and service accounts permissions required for their role
  • Enable and review file‑access logging to detect and respond to unauthorized file operations

Generated by OpenCVE AI on September 20, 2026 at 23:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T20:08:42.575Z

Reserved: 2026-07-20T18:01:39.085Z

Link: CVE-2026-16335

cve-icon Vulnrichment

Updated: 2026-09-14T20:08:39.413Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:40.270

Modified: 2026-09-16T19:22:22.797

Link: CVE-2026-16335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')