Impact
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a path traversal flaw in the archive extraction routine that allows a remote authenticated attacker to create arbitrary files on the host. The vulnerability is identified as CWE‑22 and can be leveraged to write files such as configuration overrides, scripts, or binaries.
Affected Systems
The affected product is IBM DataStage on Cloud Pak for Data version 5.4.0.0. IBM explicitly recommends upgrading to 5.4 patch 5 or later; the fix is detailed in the IBM documentation linked in the advisory.
Risk and Exploitability
The flaw carries a CVSS score of 9.1. EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to the DataStage service; once authorized, an attacker can supply a crafted archive that, upon extraction, writes files out of the intended directory, potentially allowing further compromise.
OpenCVE Enrichment