Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.
Published: 2026-09-10
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via unauthorized deletion of RabbitMQ queues or exchanges
Action: Patch Now
AI Analysis

Impact

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an improper authorization flaw (CWE-285) that arbitrary RabbitMQ queues or exchanges, disrupting data pipelines and potentially bringing services to a halt. The fault lies in the insufficient validation of privileges when performing queue or exchange deletions, which can be leveraged to cause a denial of service by removing critical messaging resources.

Affected Systems

The vulnerability affects IBM DataStage on Cloud Pak for Data version 5.4.0.0. Only installations of this specific release are impacted; newer releases patched through 5.4 patch 5 or later contain the fix.

Risk and Exploitability

The CVSS score of 8.5 classifies this issue as high severity, indicating a substantial impact on availability. EPSS data is not available, so the exact exploitation probability cannot be quantified, but the missing EPSS should be interpreted as a lack of publicly reported exploitation rather than proof of safety. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, reducing immediate operational concern but still necessitating remediation. The attack vector is inferred to be remote and authenticated, as the flaw only applies to users with valid credentials, and the attacker must target RabbitMQ interactions within the DataStage environment.

Generated by OpenCVE AI on September 11, 2026 at 04:25 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade IBM DataStage on Cloud Pak for Data to 5.4 patch 5 or later following the official IBM instructions for this release.
  • Enforce least‑privilege authentication for users interacting with RabbitMQ to prevent elevation of privilege to delete queues or exchanges.
  • Implement monitoring on RabbitMQ to detect abnormal deletions and alert administrators to potential abuse of the service.

Generated by OpenCVE AI on September 11, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:36:35.308Z

Reserved: 2026-08-26T11:02:22.248Z

Link: CVE-2026-80436

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T22:17:01.440

Modified: 2026-09-10T22:17:01.440

Link: CVE-2026-80436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:30:07Z

Weaknesses