Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.
Published: 2026-09-10
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A path traversal flaw in IBM DataStage on Cloud Pak for Data 5.4.0.0 permits a remote attacker with authenticated access to overwrite ruleset files that belong to other tenants. By modifying these files, the attacker can alter the processing logic used by other customers, potentially gaining unauthorized control over data flows or facilitating additional attacks such as data tampering or covert exfiltration. The weakness is a classic example of CWE‑22 traversal into protected directories.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. The fix is available in patch 5 of the 5.4 release. Upgrading to DataStage on Cloud Pak for Data 5.4 patch 5 or later addresses the vulnerability.

Risk and Exploitability

The CVSS score of 8.5 signals high severity. Although the EPSS score is not available, the flaw requires authentication but does not require any additional privileges. Any valid credentials allow exploitation of the path traversal to modify other tenants’ rules. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been reported yet, but the potential impact justifies prompt remediation.

Generated by OpenCVE AI on September 11, 2026 at 04:48 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade to DataStage on Cloud Pak for Data 5.4 patch 5 or later by following IBM’s documented upgrade procedures
  • After upgrading, review tenant isolation settings and monitor access logs to ensure no unauthorized file modifications occur
  • Apply IBM recommended configuration changes to enforce strict tenant isolation after patching

Generated by OpenCVE AI on September 11, 2026 at 04:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0:*:*:*:*:*:*:*

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T15:05:36.571Z

Reserved: 2026-08-26T23:59:09.876Z

Link: CVE-2026-81540

cve-icon Vulnrichment

Updated: 2026-09-15T15:05:32.424Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:02.530

Modified: 2026-09-16T00:45:42.110

Link: CVE-2026-81540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:15:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')