ZeroHour

CVE-2026-16335

moderate

Authenticated Path Traversal in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a path traversal vulnerability (CWE-22) that allows a remote authenticated attacker to read, write, or delete arbitrary files on the affected system. The flaw is triggered by an authenticated user manipulating file path parameters in DataStage requests so that they escape their intended directory. Successful exploitation gives the attacker high-impact compromise of confidentiality and integrity — exfiltration of sensitive data or files plus unauthorized modification or deletion — though availability is not directly affected, per the CVSS 3.1 base score of 8.1. Only deployments of DataStage on Cloud Pak for Data at version 5.4.0.0 are affected, and exploitation requires valid credentials, which narrows the attacker pool to insiders or attackers with stolen credentials. There is no evidence of exploitation in the wild, no public proof of concept, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply IBM's fix for this vulnerability as described in the IBM PSIRT security bulletin for DataStage on Cloud Pak for Data 5.4.0.0 and upgrade off the affected version. Until patched, restrict DataStage access to trusted, authenticated users only, audit DataStage account activity and logs for anomalous file access or path manipulation, and enforce least-privilege credentials so a compromised account cannot reach sensitive files. Because exploitation requires authentication, rotating and tightening credentials on DataStage reduces practical risk.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderatelikely low thousands of enterprise deployments globally (exact count unknown) — DataStage is a widely deployed enterprise ETL tool running inside Cloud Pak for Data at large organizations (banks, insurers, telecoms), which typically number in the low thousands of installations worldwide, and these deployments are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.

Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.