Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Data disclosure via absolute-path traversal with authenticated access
Action: Patch Immediately
AI Analysis

Impact

The flaw in IBM DataStage on Cloud Pak for Data 5.4.0.0 allows attackers who can authenticate to the system to exploit an absolute-path traversal vulnerability. This flaw can enable reading files outside the intended application directory, potentially exposing confidential data stored on the host filesystem. The weakness is classified as CWE-36, indicating improper handling of path traversal inputs.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. IBM recommends upgrading to patch 5 or any later release in the 5.4 series, which resolves the path-traversal issue.

Risk and Exploitability

The high CVSS score of 8.8 indicates a high‑severity flaw, and while no EPSS score is listed, the vulnerability is not listed in the KEV catalog. Exploitation requires valid authentication. It is inferred that privileged users or compromised credentials could be leveraged to access sensitive filesystem data. It is also inferred that the attack vector could lead to system‑wide confidentiality loss if the attacker’s account has sufficient access rights.

Generated by OpenCVE AI on September 11, 2026 at 06:04 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade IBM DataStage on Cloud Pak for Data to patch 5 of the 5.4 series or a later release, following the IBM instructions available in the product documentation.
  • If an upgrade cannot immediately be applied, restrict user accounts to the minimum necessary privileges so that only highly trusted or least‑privileged accounts can perform operations that involve file paths.
  • Implement monitoring of file‑access logs and audit trails for anomalous or repeated attempts to read files outside the intended application directory.

Generated by OpenCVE AI on September 11, 2026 at 06:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0:*:*:*:*:*:*:*

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-36
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-11T14:42:18.033Z

Reserved: 2026-08-28T04:34:53.912Z

Link: CVE-2026-82092

cve-icon Vulnrichment

Updated: 2026-09-11T14:42:11.163Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:03.370

Modified: 2026-09-16T00:41:54.250

Link: CVE-2026-82092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T18:30:13Z

Weaknesses
  • CWE-36

    Absolute Path Traversal