Impact
An absolute‑path traversal flaw in IBM DataStage on Cloud Pak for Data 5.4.0.0 permits a remote authenticated user to manipulate file paths and read arbitrary files on the underlying file system. This vulnerability, categorized as CWE‑22, can lead to disclosure of confidential information such as configuration files or user credentials if accessed through the application.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. The vendor recommends upgrading to patch 5 or any later version, which removes the flaw. No other vendors or products are listed, and the CPE entry points to this specific version.
Risk and Exploitability
The CVSS base score of 8.8 signals high severity. EPSS is not published, and the issue is not in the CISA KEV catalog, indicating no known public exploitation. Exploitation requires existing authentication; once credentials are obtained, an attacker can manipulate paths and retrieve any file accessible to the service account. The overall risk is high for environments where shared credentials or weak access controls allow unauthorized users to log in.
OpenCVE Enrichment