CVE-2026-82100
9.6IBM · DataStage on Cloud Pak for Data
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to path traversal, which could allow a remote authenticated attacker to trigger a denial of service or unauthorized file manipulation.
Executive summary
A path traversal vulnerability in IBM DataStage on Cloud Pak for Data allows a remote authenticated attacker to disrupt services or compromise system integrity.
Vulnerability
This vulnerability is a path traversal flaw (CWE-22) that permits an authenticated attacker with low privileges to manipulate file paths, resulting in a denial of service or potential impact on system files. The vulnerability requires the attacker to be authenticated to the target application.
Business impact
The exploitation of this vulnerability poses a significant risk to business operations due to the potential for service disruption and unauthorized data access. With a CVSS score of 9.6, this flaw is categorized as critical, indicating that successful exploitation could lead to severe impacts on both system availability and data integrity within the Cloud Pak for Data environment.
Remediation
Immediate Action: Upgrade IBM DataStage on Cloud Pak for Data to version 5.4 patch 5 or later as specified in the official IBM support documentation.
Proactive Monitoring: Monitor system logs for unusual file access patterns or unexpected application crashes that may indicate an attempt to exploit path traversal vectors.
Compensating Controls: Implement strict file system permissions and utilize a Web Application Firewall to filter requests containing directory traversal sequences like dot-dot-slash patterns.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The critical nature of this vulnerability, combined with the potential for service denial, necessitates immediate patching. Organizations running IBM DataStage on Cloud Pak for Data version 5.4.0.0 should prioritize the upgrade to patch 5 or higher during the next available maintenance window to mitigate the risk of unauthorized system disruption.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section