Impact
IBM DataStage on Cloud Pak for Data version 5.4.0.0 allows an authenticated user to write arbitrary files because the software does not properly validate file paths. This flaw can be used to overwrite or create critical configuration or executable files, potentially leading to execution of malicious code and full compromise of the system by an adversary who has legitimate credentials.
Affected Systems
IBM DataStage on Cloud Pak for Data 5.4.0.0 is the only version currently listed as affected; no other product versions are noted in the CNA data.
Risk and Exploitability
The CVSS score of 9.9 classifies the issue as critical, and the EPSS score is below 1%, indicating a low overall probability of exploitation yet still serious. The flaw is not listed in CISA’s KEV catalog, but it remains a high‑severity vulnerability because it permits a remote authenticated attacker to write files on the host. Exploitation requires valid credentials with sufficient application write permissions, making organizations that use broad user privileges or have weak authentication controls particularly vulnerable.
OpenCVE Enrichment