CVE-2026-80378

8.5

IBM · DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an improper authorization flaw that allows an authenticated remote attacker to cause a denial of service condition.

Executive summary

A remote authenticated attacker can trigger a denial of service condition in IBM DataStage on Cloud Pak for Data 5.4.0.0 due to a flaw in authorization handling.

Vulnerability

This vulnerability is caused by improper authorization (CWE-285), which allows a remote user with authenticated access to perform actions that lead to a denial of service. The CVSS vector of AV:N/AC:L/PR:L/UI:N confirms that the attacker requires low-level privileges but does not require any user interaction to trigger the fault.

Business impact

The ability for an authenticated attacker to cause a denial of service presents a significant threat to operational availability and business continuity. With a CVSS score of 8.5, this high-severity vulnerability could lead to prolonged service outages, hindering critical data processing tasks and impacting downstream business workflows that rely on the DataStage platform.

Remediation

Immediate Action: Upgrade to DataStage on Cloud Pak for Data 5.4 patch 5 or later as specified in the official IBM security bulletin.

Proactive Monitoring: Review system access logs for suspicious user activity or repeated attempts to execute unauthorized functions within the DataStage environment.

Compensating Controls: Ensure that access controls and identity management policies are strictly enforced to limit the number of users with the low-level privileges required to trigger this vulnerability.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

Given the high CVSS severity rating, organizations should prioritize the application of the vendor-supplied patch. Administrators must verify their current version and upgrade to version 5.4 patch 5 or later immediately to eliminate the risk of service disruption.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources