Impact
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows a remote authenticated attacker to execute arbitrary code by exploiting improper validation of paths during archive extraction. The vulnerability arises when archive extraction logic does not correctly sanitize file paths, enabling an attacker to place files outside the intended directories and trigger execution of malicious code. This flaw grants the attacker full control over the system executing the extraction process, compromising confidentiality, integrity, and availability of the affected platform.
Affected Systems
IBM DataStage on Cloud Pak for Data, version 5.4.0.0, is the only product identified as vulnerable. The issue affects the IBM DataStage installer environment included in the 5.4.0.0 release of the Cloud Pak for Data platform.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. No EPSS score is available, and the vulnerability is not present in CISA’s KEV catalog. The likely attack vector requires remote authenticated access; an attacker must possess valid credentials for the DataStage environment to upload and trigger the malformed archive. Once executed, the attacker gains arbitrary code execution abilities on the host system where the extraction occurs.
OpenCVE Enrichment