Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction.
Published: 2026-09-29
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows a remote authenticated attacker to execute arbitrary code by exploiting improper validation of paths during archive extraction. The vulnerability arises when archive extraction logic does not correctly sanitize file paths, enabling an attacker to place files outside the intended directories and trigger execution of malicious code. This flaw grants the attacker full control over the system executing the extraction process, compromising confidentiality, integrity, and availability of the affected platform.

Affected Systems

IBM DataStage on Cloud Pak for Data, version 5.4.0.0, is the only product identified as vulnerable. The issue affects the IBM DataStage installer environment included in the 5.4.0.0 release of the Cloud Pak for Data platform.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, indicating high severity. No EPSS score is available, and the vulnerability is not present in CISA’s KEV catalog. The likely attack vector requires remote authenticated access; an attacker must possess valid credentials for the DataStage environment to upload and trigger the malformed archive. Once executed, the attacker gains arbitrary code execution abilities on the host system where the extraction occurs.

Generated by OpenCVE AI on September 29, 2026 at 23:25 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 7 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade IBM DataStage on Cloud Pak for Data to version 5.4 patch 7 or later following IBM’s instructions.
  • Limit the ability of authenticated users to upload archives for extraction or enforce strict input validation on extraction paths.
  • After upgrade or configuration changes, verify that malicious archive paths (e.g., containing ‘../’) no longer result in code execution or unintended file writes.

Generated by OpenCVE AI on September 29, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction.
Title DataStage on Cloud Pak for Data has several vulnerabilities
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-29T21:02:00.663Z

Reserved: 2026-09-01T17:50:05.004Z

Link: CVE-2026-84421

cve-icon Vulnrichment

Updated: 2026-09-29T21:00:21.367Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:17.560

Modified: 2026-09-29T22:19:01.443

Link: CVE-2026-84421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T23:30:19Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')