ZeroHour

CVE-2026-82092

niche

Authenticated absolute path traversal in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
6.5 medium
EPSS
Published
()
Modified
AI analysis

IBM DataStage, when deployed within IBM Cloud Pak for Data 5.4.0.0, contains an absolute path traversal flaw (CWE-36), meaning the application fails to neutralize fully-qualified file paths supplied in requests and can therefore be directed to files outside the intended directory. A remote attacker who already holds valid credentials can trigger the flaw over the network by submitting a path that points at arbitrary locations on the server, such as system files. The practical payoff is disclosure of sensitive information — configuration files, secrets, or other data readable by the service — and IBM's CVSS rating of 8.8 also weights integrity and availability impacts as high. Only organizations running DataStage as part of Cloud Pak for Data version 5.4.0.0 are affected. There is currently no evidence of in-the-wild exploitation, no CISA KEV listing, and no known public proof-of-concept.

What to do: Inventory your environment to confirm whether DataStage is deployed on Cloud Pak for Data 5.4.0.0, and if so, apply the fix referenced in IBM's security bulletin as soon as it is available (IBM is the assigned CNA and will publish patched releases there). Until patched, restrict which authenticated accounts can reach DataStage file-handling functions and audit file-access logs for requests using absolute paths. Given the high CVSS score but absence of public PoCs or KEV listing, treat this as a routine high-severity patch cycle rather than an emergency.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
nichelikely hundreds to a few thousand enterprise deployments (Cloud Pak for Data 5.4.0.0 clusters with DataStage enabled) — Cloud Pak for Data with the DataStage service is an enterprise data-integration platform deployed inside private customer clusters rather than as internet-facing software, so the installed base is limited to large organizations on this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-36
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.