ZeroHour

CVE-2026-80424

moderate

Authenticated Path Traversal File Creation in IBM DataStage on Cloud Pak for Data 5.4

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to a path traversal flaw (CWE-22) that occurs during archive extraction, allowing arbitrary files to be created outside the intended extraction location. A remote attacker who holds valid, low-privileged credentials can trigger the flaw by getting the service to extract a crafted archive whose entries contain traversal paths. Because the CVSS scope is changed (S:C), the write can escape the vulnerable component and affect other parts of the deployment, producing a high integrity impact (overwriting or planting files, potentially in sensitive locations) alongside limited confidentiality and availability impact. Only organizations running DataStage on Cloud Pak for Data version 5.4.0.0 are affected. There is no evidence of active exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Check IBM's security advisory ([email protected] is the CNA) for the fixed 5.4.x refresh and apply the patch to DataStage on Cloud Pak for Data 5.4.0.0. In the meantime, limit which authenticated users can upload or trigger extraction of archives, and review file-integrity-sensitive paths writable by the DataStage service for unexpected or overwritten files.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderatelikely on the order of 1,000–10,000 enterprise clusters worldwide (no public install counts available) — DataStage on Cloud Pak for Data is an enterprise data-integration offering deployed on customer-managed OpenShift clusters that are usually kept on internal networks, so the installed base is plausibly in the low thousands of clusters, and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

In the news

No ingested article mentions this CVE yet.