Impact
The vulnerability in IBM DataStage on Cloud Pak for Data 5.4.0.0 allows a remote authenticated attacker to manipulate runtime caches through an insecure direct object reference, resulting in a denial of service. The weakness arises from a missing authorization check (CWE‑639) and enables attackers to disrupt service availability by corrupting cached objects used by the application.
Affected Systems
IBM DataStage on Cloud Pak for Data, version 5.4.0.0, is the affected product. Upgrading to patch 5 (5.4 patch 5) or later resolves the issue.
Risk and Exploitability
With a CVSS score of 7.4 the vulnerability is categorized as high severity. EPSS information is not available, and the vulnerability is not listed in CISA's KEV catalog. The attack requires legitimate credentials and remote access, so the attack vector is likely network‑based with authentication. Once the object reference flaw is exploited, the attacker can cause a denial of service by corrupting runtime caches, affecting the availability of the affected system.
OpenCVE Enrichment