Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote authenticated information disclosure
Action: Patch Immediately
AI Analysis

Impact

An absolute‑path traversal flaw in IBM DataStage on Cloud Pak for Data 5.4.0.0 permits a remote authenticated user to manipulate file paths and read arbitrary files on the underlying file system. This vulnerability, categorized as CWE‑22, can lead to disclosure of confidential information such as configuration files or user credentials if accessed through the application.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. The vendor recommends upgrading to patch 5 or any later version, which removes the flaw. No other vendors or products are listed, and the CPE entry points to this specific version.

Risk and Exploitability

The CVSS base score of 8.8 signals high severity. EPSS is not published, and the issue is not in the CISA KEV catalog, indicating no known public exploitation. Exploitation requires existing authentication; once credentials are obtained, an attacker can manipulate paths and retrieve any file accessible to the service account. The overall risk is high for environments where shared credentials or weak access controls allow unauthorized users to log in.

Generated by OpenCVE AI on September 11, 2026 at 04:31 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade IBM DataStage on Cloud Pak for Data to version 5.4 patch 5 or later following IBM’s instructions.
  • Restrict file‑system permissions so the application can access only the directories it needs.
  • Implement input validation to reject paths containing '..' or absolute components before they reach file‑system APIs.

Generated by OpenCVE AI on September 11, 2026 at 04:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-11T17:38:13.791Z

Reserved: 2026-08-27T01:06:13.960Z

Link: CVE-2026-81554

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:02.937

Modified: 2026-09-16T00:44:18.187

Link: CVE-2026-81554

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:00:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')