Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.
Published: 2026-09-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Manipulation
Action: Patch Now
AI Analysis

Impact

The vulnerability is a path traversal flaw that permits a remote authenticated attacker to read, write, or delete arbitrary files on the underlying system. The flaw is classified under CWE‑22, indicating improper handling of user‑supplied path components. By exploiting this weakness, an attacker can compromise the confidentiality and integrity of tampering, or execution of malicious code if privileged files are affected.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. IBM recommends upgrading to 5.4 patch 5 or newer to eliminate the flaw.

Risk and Exploitability

The flaw has a CVSS score of 8.1, signifying high severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploits at this time. The attack would require remote authenticated access; once logged in, an attacker can exploit the path traversal to perform arbitrary file operations.

Generated by OpenCVE AI on September 15, 2026 at 12:53 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Apply IBM DataStage on Cloud Pak for Data 5.4 patch 5 or later
  • Restrict user and service accounts so they have only the minimum file‑system permissions required for their role
  • Enable and review file‑access logging to detect and respond to unauthorized file operations

Generated by OpenCVE AI on September 15, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T20:08:42.575Z

Reserved: 2026-07-20T18:01:39.085Z

Link: CVE-2026-16335

cve-icon Vulnrichment

Updated: 2026-09-14T20:08:39.413Z

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:40.270

Modified: 2026-09-14T20:16:40.270

Link: CVE-2026-16335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:00:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')