Impact
A path traversal flaw in IBM DataStage on Cloud Pak for Data 5.4.0.0 permits a remote attacker with authenticated access to overwrite ruleset files that belong to other tenants. By modifying these files, the attacker can alter the processing logic used by other customers, potentially gaining unauthorized control over data flows or facilitating additional attacks such as data tampering or covert exfiltration. The weakness is a classic example of CWE‑22 traversal into protected directories.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. The fix is available in patch 5 of the 5.4 release. Upgrading to DataStage on Cloud Pak for Data 5.4 patch 5 or later addresses the vulnerability.
Risk and Exploitability
The CVSS score of 8.5 signals high severity. Although the EPSS score is not available, the flaw requires authentication but does not require any additional privileges. Any valid credentials allow exploitation of the path traversal to modify other tenants’ rules. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been reported yet, but the potential impact justifies prompt remediation.
OpenCVE Enrichment