Impact
A flaw exists when DataStage concatenates three caller‑supplied strings into a String.format path that points to the shared /ds‑storage RWX PVC and then returns the requested file without applying any project ACLs. The vulnerability allows pure IDOR combined with directory traversal. Although only job.log and error.log files are exposed, those logs routinely contain connection strings, encrypted ciphertexts, and customer data samples, enabling an attacker to read sensitive information from other tenants.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. No other versions are currently listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.7 indicates a medium‑to‑high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the issue by crafting a request that bypasses ACL checks and traverses to locate log files on the shared PVC, without needing privileged credentials. Because the logs often contain sensitive information, the potential impact is high, making exploitation likely in exposed environments.
OpenCVE Enrichment