Impact
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a path traversal flaw that permits an authenticated user to write to or delete files on shared storage. This flaw originates from insufficient validation of user‑supplied file paths, enabling the attacker to manipulate critical data, disrupt services, or compromise data integrity and confidentiality.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. IBM recommends upgrading to patch 5 or any later patch, following the upgrade procedures documented on IBM’s support site.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity. No EPSS score is available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote; an attacker with legitimate authentication can leverage the path traversal to tamper with or erase files on shared volumes.
OpenCVE Enrichment