Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection strings, {dsnextenc} ciphertexts (decryptable via d2-f023), and customer-data row samples. This is the operator's tenant-to-tenant PVC-leakage threat verbatim; MEDIUM→HIGH via threat match.
Published: 2026-09-10
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: IDOR and path traversal allowing read of sensitive log files
Action: Patch immediately
AI Analysis

Impact

A flaw exists when DataStage concatenates three caller‑supplied strings into a String.format path that points to the shared /ds‑storage RWX PVC and then returns the requested file without applying any project ACLs. The vulnerability allows pure IDOR combined with directory traversal. Although only job.log and error.log files are exposed, those logs routinely contain connection strings, encrypted ciphertexts, and customer data samples, enabling an attacker to read sensitive information from other tenants.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. No other versions are currently listed as vulnerable.

Risk and Exploitability

The CVSS score of 7.7 indicates a medium‑to‑high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the issue by crafting a request that bypasses ACL checks and traverses to locate log files on the shared PVC, without needing privileged credentials. Because the logs often contain sensitive information, the potential impact is high, making exploitation likely in exposed environments.

Generated by OpenCVE AI on September 11, 2026 at 04:47 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade DataStage on Cloud Pak for Data to patch 5 or later of the 5.4 release line
  • Follow IBM’s upgrade instructions at https://www.ibm.com/docs/en/software-hub/5.4.x
  • Implement or enforce project access controls on the /ds‑storage PVC to limit read access to log files

Generated by OpenCVE AI on September 11, 2026 at 04:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0:*:*:*:*:*:*:*

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection strings, {dsnextenc} ciphertexts (decryptable via d2-f023), and customer-data row samples. This is the operator's tenant-to-tenant PVC-leakage threat verbatim; MEDIUM→HIGH via threat match.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-639
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T15:08:01.498Z

Reserved: 2026-08-26T17:03:24.254Z

Link: CVE-2026-81210

cve-icon Vulnrichment

Updated: 2026-09-15T15:07:57.416Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:01.837

Modified: 2026-09-16T00:46:04.780

Link: CVE-2026-81210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:00:13Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key