Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.
Published: 2026-09-10
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in IBM DataStage on Cloud Pak for Data 5.4.0.0 allows a remote authenticated attacker to manipulate runtime caches through an insecure direct object reference, resulting in a denial of service. The weakness arises from a missing authorization check (CWE‑639) and enables attackers to disrupt service availability by corrupting cached objects used by the application.

Affected Systems

IBM DataStage on Cloud Pak for Data, version 5.4.0.0, is the affected product. Upgrading to patch 5 (5.4 patch 5) or later resolves the issue.

Risk and Exploitability

With a CVSS score of 7.4 the vulnerability is categorized as high severity. EPSS information is not available, and the vulnerability is not listed in CISA's KEV catalog. The attack requires legitimate credentials and remote access, so the attack vector is likely network‑based with authentication. Once the object reference flaw is exploited, the attacker can cause a denial of service by corrupting runtime caches, affecting the availability of the affected system.

Generated by OpenCVE AI on September 11, 2026 at 04:23 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Apply IBM DataStage on Cloud Pak for Data 5.4 patch 5 or later following IBM’s instructions
  • Restrict access to runtime cache objects by enforcing least‑privilege user roles
  • Monitor service logs for abnormal cache manipulation attempts to detect potential exploitation

Generated by OpenCVE AI on September 11, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-639
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:37:50.895Z

Reserved: 2026-08-26T10:56:06.778Z

Link: CVE-2026-80434

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T22:17:01.303

Modified: 2026-09-10T22:17:01.303

Link: CVE-2026-80434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:15:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key