CVE-2026-16338
9.9IBM · DataStage on Cloud Pak for Data
IBM DataStage on Cloud Pak for Data is vulnerable to arbitrary file write attacks by remote authenticated users due to improper validation of file paths.
Executive summary
A critical vulnerability in IBM DataStage on Cloud Pak for Data allows authenticated remote attackers to perform arbitrary file writes, creating a significant risk of system compromise.
Vulnerability
This vulnerability, categorized as CWE-73, stems from improper validation of user controlled file paths. It allows a remote attacker with authenticated access to write arbitrary files to the underlying system.
Business impact
The ability to perform arbitrary file writes can lead to full system compromise, including the injection of malicious scripts or the modification of sensitive configuration files. Given the CVSS score of 9.9, this vulnerability poses an extreme risk to confidentiality, integrity, and availability. Successful exploitation could result in unauthorized data access, service disruption, and complete loss of control over the affected environment.
Remediation
Immediate Action: Upgrade IBM DataStage on Cloud Pak for Data to version 5.4 patch 5 or later as instructed in the vendor documentation.
Proactive Monitoring: Review system access logs for anomalous file write operations or unexpected modifications to configuration directories.
Compensating Controls: Implement strict file system permissions and employ security monitoring tools to detect unauthorized process activity or unexpected file creation events.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical severity of this arbitrary file write vulnerability, immediate action is required to patch the affected systems. Administrators should prioritize upgrading to the specified fixed version to eliminate the risk of remote exploitation and maintain the integrity of the Cloud Pak for Data environment.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section