Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
Published: 2026-09-10
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Creation
Action: Immediate Patch
AI Analysis

Impact

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a path traversal flaw in the archive extraction routine that allows a remote authenticated attacker to create arbitrary files on the host. The vulnerability is identified as CWE‑22 and can be leveraged to write files such as configuration overrides, scripts, or binaries.

Affected Systems

The affected product is IBM DataStage on Cloud Pak for Data version 5.4.0.0. IBM explicitly recommends upgrading to 5.4 patch 5 or later; the fix is detailed in the IBM documentation linked in the advisory.

Risk and Exploitability

The flaw carries a CVSS score of 9.1. EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to the DataStage service; once authorized, an attacker can supply a crafted archive that, upon extraction, writes files out of the intended directory, potentially allowing further compromise.

Generated by OpenCVE AI on September 11, 2026 at 04:24 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Apply the IBM‑proposed patch to upgrade DataStage on Cloud Pak for Data to 5.4 patch 5 or later, following the IBM documentation.
  • Adjust the archive extraction configuration to enforce strict directory validation, ensuring that extracted file names cannot escape the intended target folder.
  • Restrict or disable uploading of archive files into DataStage until the update is applied to prevent potential exploitation of the flaw.

Generated by OpenCVE AI on September 11, 2026 at 04:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:37:30.730Z

Reserved: 2026-08-26T10:38:58.706Z

Link: CVE-2026-80424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T22:17:01.163

Modified: 2026-09-10T22:17:01.163

Link: CVE-2026-80424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:45:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')