CVE-2026-81551

8.8

IBM · DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to path traversal, allowing a remote authenticated attacker to write or delete files on shared storage.

Executive summary

An authenticated remote attacker can exploit a path traversal vulnerability in IBM DataStage on Cloud Pak for Data 5.4.0.0 to perform unauthorized file operations on shared storage.

Vulnerability

This vulnerability is a path traversal flaw (CWE-22) that occurs because the application fails to properly sanitize user input when interacting with shared storage. A remote attacker with low-level authenticated access can manipulate file paths to write to or delete arbitrary files, potentially leading to full system compromise.

Business impact

The ability to write to or delete files on shared storage poses a severe risk to data integrity and system availability. Successful exploitation could result in the destruction of critical business data, the injection of malicious files, or the disruption of data processing workflows. Given the CVSS score of 8.8, this vulnerability is classified as high severity and requires immediate attention to prevent unauthorized access to sensitive infrastructure.

Remediation

Immediate Action: Upgrade the IBM DataStage on Cloud Pak for Data environment to version 5.4 patch 5 or later as specified in the official IBM support documentation.

Proactive Monitoring: Review system and access logs for unusual file system activity or attempts to access directories outside of expected application paths.

Compensating Controls: Ensure that the service account running DataStage is constrained by operating system level permissions to only the minimum necessary files and directories required for its function.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant risk to the integrity of the DataStage environment. Security teams should prioritize the application of the vendor-supplied patch to version 5.4 patch 5. If patching is not immediately feasible, restrict network access to the affected service and ensure that all file system permissions are hardened to prevent unauthorized modifications by the application service account.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources