ZeroHour

CVE-2026-80434

moderate

IDOR in IBM DataStage on Cloud Pak for Data 5.4.0.0 lets authenticated users trigger DoS

CVSS 3.1
5.0 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-80434 is an insecure direct object reference (CWE-639) in the runtime cache handling of IBM DataStage on Cloud Pak for Data, affecting version 5.4.0.0. A remote attacker with low-privilege authenticated access can send crafted requests that reference runtime cache objects they are not authorized to touch, manipulating caches shared across the scoped environment (the CVSS scope is 'changed', meaning other components can be impacted). Successful manipulation causes a denial of service for DataStage jobs and services, with the CVSS vector also indicating a low level of confidentiality and integrity impact. Only organizations running DataStage on Cloud Pak for Data 5.4.0.0 are affected. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and no exploitation has been reported in the wild.

What to do: Upgrade DataStage on Cloud Pak for Data from 5.4.0.0 to the fixed fix pack or later release identified in IBM's security bulletin for this CVE. Until patched, restrict which authenticated low-privilege accounts can invoke jobs or interact with runtime cache resources, and monitor for unusual cache-related job failures or service disruptions. There is no known public exploit, so prioritize patching where untrusted or broadly-issued low-privilege credentials can reach DataStage.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderatelikely in the low thousands of enterprise deployments (exact counts unknown) — Cloud Pak for Data is an on-premises/private-cloud enterprise data platform with no public install counts, so the estimate is based on the assumption of thousands of IBM enterprise customer deployments running this specific 5.4.0.0 release…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.