Impact
The vulnerability in DataStage on Cloud Pak for Data 5.4.0.0 allows a remote authenticated attacker to trigger a denial‑of‑service condition by exploiting improper authorization checks. The flaw is a credential‑validation weakness (CWE‑285) that removes a necessary permission barrier, letting the attacker repeatedly abort or stall job processing, thereby impacting availability for the entire DataStage service.
Affected Systems
Affected systems are IBM DataStage on Cloud Pak for Data, version 5.4.0.0. IBM recommends upgrading to patch 5 or later of family. No other versions were reported as affected in the advisory.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity level. Although an lack of a publicly reported exploit and absence from CISA KEV suggest a lower exploitation probability at this time. The attack requires valid user credentials, so the risk is limited to accounts with administrative or privileged roles that can initiate DataStage jobs. However, because the denial‑of‑service can shut down critical data pipelines, a determined insider or compromised credential holder could inflict significant disruption.
OpenCVE Enrichment