Impact
This vulnerability arises from improper authentication handling in IBM DataStage on Cloud Pak for flaw to retrieve sensitive weakness is an authentication failure (CWE-287) that allows attackers to gain elevated access beyond what is intended by the system.
Affected Systems
It affects IBM DataStage on Cloud Pak for Data version 5.4.0.0 installed in Cloud Pak environments. The official advisory recommends that any deployments running this version be upgraded.
Risk and Exploitability
The CVSS score of 9.6 marks this as a critical vulnerability, and while the EPSS score is not available, the lack of KEV listing does not diminish the risk of exploitation. The likely attack vector is remote, authenticated access, meaning an adversary with valid credentials can leverage the flaw from any network location that can reach the application.
OpenCVE Enrichment