Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Arbitrary File Write and Delete
Action: Immediate Patch
AI Analysis

Impact

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a path traversal flaw that permits an authenticated user to write to or delete files on shared storage. This flaw originates from insufficient validation of user‑supplied file paths, enabling the attacker to manipulate critical data, disrupt services, or compromise data integrity and confidentiality.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. IBM recommends upgrading to patch 5 or any later patch, following the upgrade procedures documented on IBM’s support site.

Risk and Exploitability

The CVSS score of 8.8 classifies the vulnerability as high severity. No EPSS score is available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote; an attacker with legitimate authentication can leverage the path traversal to tamper with or erase files on shared volumes.

Generated by OpenCVE AI on September 11, 2026 at 04:30 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade IBM DataStage on Cloud Pak for Data to patch 5 or later following IBM’s upgrade instructions.
  • Restrict authenticated user permissions so that only trusted users have write or delete capabilities on shared storage.
  • Implement input validation or directory‑locking mechanisms in custom code and scripts that interact with shared storage to prevent path traversal.
  • Consider isolating shared storage or employing file‑system permissions to limit which directories are writable by application processes.

Generated by OpenCVE AI on September 11, 2026 at 04:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0:*:*:*:*:*:*:*

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T15:04:27.746Z

Reserved: 2026-08-27T00:44:37.024Z

Link: CVE-2026-81551

cve-icon Vulnrichment

Updated: 2026-09-15T15:04:22.176Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:02.797

Modified: 2026-09-16T00:43:28.607

Link: CVE-2026-81551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:30:09Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')