Impact
The flaw in IBM DataStage on Cloud Pak for Data 5.4.0.0 allows attackers who can authenticate to the system to exploit an absolute-path traversal vulnerability. This flaw can enable reading files outside the intended application directory, potentially exposing confidential data stored on the host filesystem. The weakness is classified as CWE-36, indicating improper handling of path traversal inputs.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. IBM recommends upgrading to patch 5 or any later release in the 5.4 series, which resolves the path-traversal issue.
Risk and Exploitability
The high CVSS score of 8.8 indicates a high‑severity flaw, and while no EPSS score is listed, the vulnerability is not listed in the KEV catalog. Exploitation requires valid authentication. It is inferred that privileged users or compromised credentials could be leveraged to access sensitive filesystem data. It is also inferred that the attack vector could lead to system‑wide confidentiality loss if the attacker’s account has sufficient access rights.
OpenCVE Enrichment