Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.
Published: 2026-09-10
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in DataStage on Cloud Pak for Data 5.4.0.0 allows a remote authenticated attacker to trigger a denial‑of‑service condition by exploiting improper authorization checks. The flaw is a credential‑validation weakness (CWE‑285) that removes a necessary permission barrier, letting the attacker repeatedly abort or stall job processing, thereby impacting availability for the entire DataStage service.

Affected Systems

Affected systems are IBM DataStage on Cloud Pak for Data, version 5.4.0.0. IBM recommends upgrading to patch 5 or later of family. No other versions were reported as affected in the advisory.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity level. Although an lack of a publicly reported exploit and absence from CISA KEV suggest a lower exploitation probability at this time. The attack requires valid user credentials, so the risk is limited to accounts with administrative or privileged roles that can initiate DataStage jobs. However, because the denial‑of‑service can shut down critical data pipelines, a determined insider or compromised credential holder could inflict significant disruption.

Generated by OpenCVE AI on September 11, 2026 at 04:21 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade DataStage on Cloud Pak for Data to patch 5 or later of the 5.4 release, following IBM’s official patching guidance.
  • Apply the IBM patch according to the detailed instructions provided in the IBM documentation for version 5.4.x.
  • Enforce strict role‑based access controls so that only authorized personnel can execute or manage DataStage jobs, reducing the risk of improper authorization leading to service disruption.

Generated by OpenCVE AI on September 11, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:39:26.386Z

Reserved: 2026-08-26T10:08:05.022Z

Link: CVE-2026-80378

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T22:17:00.910

Modified: 2026-09-10T22:17:00.910

Link: CVE-2026-80378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:15:16Z

Weaknesses