Impact
The vulnerability allows a remote authenticated attacker to exploit a path traversal flaw and trigger a denial of service, affecting application availability. The specific location within DataStage on Cloud Pak for Data is not detailed, but it is inferred that it concerns file path handling. No other confidentiality or integrity impact is explicitly described.
Affected Systems
IBM DataStage on Cloud Pak for Data 5.4.0.0 is affected. Upgrading to 5.4 patch 5 or later, as released by IBM, removes the vulnerability. No additional vendors or versions are listed.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, so there is no known public exploitation. The likely attack vector is a remote authenticated connection to the affected application, where an attacker can supply crafted paths to trigger the denial of service.
OpenCVE Enrichment