CVE-2026-81540

8.5

IBM · DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a path traversal vulnerability that permits a remote authenticated attacker to overwrite ruleset files belonging to other tenants.

Executive summary

A high-severity path traversal vulnerability in IBM DataStage on Cloud Pak for Data allows authenticated attackers to perform unauthorized file modifications across tenant boundaries.

Vulnerability

This is a path traversal flaw (CWE-22) occurring within the application, where improper limitation of a pathname allows a remote authenticated attacker to escape intended directories and overwrite critical ruleset files associated with other tenants.

Business impact

The ability to overwrite ruleset files poses a significant risk to data integrity and multi-tenant isolation within the Cloud Pak for Data environment. Given the high CVSS score of 8.5, this vulnerability could lead to unauthorized configuration changes, potential service disruption, or the compromise of logic governing data processing across different business units.

Remediation

Immediate Action: Upgrade to DataStage on Cloud Pak for Data 5.4 patch 5 or later as specified in the IBM security advisory.

Proactive Monitoring: Review system access logs for unusual file write operations or path traversal attempts, specifically targeting directories associated with tenant configurations.

Compensating Controls: Ensure strict access control policies are enforced for all authenticated users, and consider implementing file integrity monitoring to detect unauthorized changes to ruleset files.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a critical failure in multi-tenant isolation that could have severe operational consequences. Security teams should prioritize the deployment of the 5.4 patch 5 update to ensure that tenant data and configuration logic remain protected from unauthorized modification.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources