CVE-2026-81554

8.8

IBM · DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to an absolute-path traversal flaw, allowing remote authenticated attackers to access sensitive information.

Executive summary

A high-severity path traversal vulnerability in IBM DataStage on Cloud Pak for Data allows authenticated remote attackers to compromise sensitive system files and data.

Vulnerability

This is an improper limitation of a pathname to a restricted directory (CWE-22) that enables absolute path traversal. An attacker with authenticated access can leverage this flaw to read or manipulate files outside of the intended directory structure.

Business impact

Successful exploitation of this vulnerability poses a significant risk to data confidentiality and integrity. Given the CVSS score of 8.8, an attacker could potentially gain unauthorized access to critical configuration files or sensitive business data, leading to a full compromise of the application environment.

Remediation

Immediate Action: Upgrade your installation to version 5.4 patch 5 or later as specified in the official IBM support documentation.

Proactive Monitoring: Review system and application access logs for unusual file access patterns or attempts to traverse directory structures using absolute path indicators.

Compensating Controls: Implement strict file system permissions and ensure that the application process operates with the least privilege necessary to limit the impact of a potential traversal.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this flaw, combined with the potential for unauthorized data access, necessitates immediate attention. IT administrators should prioritize the deployment of the 5.4 patch 5 update to remediate this vulnerability and prevent potential exploitation of the underlying path traversal mechanism.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources