Impact
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an improper authorization flaw (CWE-285) that arbitrary RabbitMQ queues or exchanges, disrupting data pipelines and potentially bringing services to a halt. The fault lies in the insufficient validation of privileges when performing queue or exchange deletions, which can be leveraged to cause a denial of service by removing critical messaging resources.
Affected Systems
The vulnerability affects IBM DataStage on Cloud Pak for Data version 5.4.0.0. Only installations of this specific release are impacted; newer releases patched through 5.4 patch 5 or later contain the fix.
Risk and Exploitability
The CVSS score of 8.5 classifies this issue as high severity, indicating a substantial impact on availability. EPSS data is not available, so the exact exploitation probability cannot be quantified, but the missing EPSS should be interpreted as a lack of publicly reported exploitation rather than proof of safety. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, reducing immediate operational concern but still necessitating remediation. The attack vector is inferred to be remote and authenticated, as the flaw only applies to users with valid credentials, and the attacker must target RabbitMQ interactions within the DataStage environment.
OpenCVE Enrichment