CVE-2026-80424
moderateAuthenticated Path Traversal File Creation in IBM DataStage on Cloud Pak for Data 5.4
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to a path traversal flaw (CWE-22) that occurs during archive extraction, allowing arbitrary files to be created outside the intended extraction location. A remote attacker who holds valid, low-privileged credentials can trigger the flaw by getting the service to extract a crafted archive whose entries contain traversal paths. Because the CVSS scope is changed (S:C), the write can escape the vulnerable component and affect other parts of the deployment, producing a high integrity impact (overwriting or planting files, potentially in sensitive locations) alongside limited confidentiality and availability impact. Only organizations running DataStage on Cloud Pak for Data version 5.4.0.0 are affected. There is no evidence of active exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Check IBM's security advisory ([email protected] is the CNA) for the fixed 5.4.x refresh and apply the patch to DataStage on Cloud Pak for Data 5.4.0.0. In the meantime, limit which authenticated users can upload or trigger extraction of archives, and review file-integrity-sensitive paths writable by the DataStage service for unexpected or overwritten files.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.