ZeroHour

CVE-2026-82100

moderate

Authenticated Path Traversal DoS in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
6.5 medium
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a path traversal vulnerability (CWE-22) that allows a remote attacker who already holds valid credentials to submit crafted paths that escape the intended directory boundary. IBM describes the outcome as a denial of service, but the critical 9.6 CVSS vector additionally scores high integrity impact and a changed scope, indicating the traversal can affect resources beyond the vulnerable component's security scope (no confidentiality impact is scored). Any organization running DataStage on Cloud Pak for Data version 5.4.0.0 is affected, and because exploitation requires only low-privileged authenticated network access with no user interaction, any user with access to the DataStage service is a potential attacker. There are no reports of in-the-wild exploitation, no known public proof of concept, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog.

What to do: Inventory Cloud Pak for Data deployments running DataStage and identify any on version 5.4.0.0, then consult IBM's security bulletin ([email protected] is the CNA) for the fixed release and upgrade when it is published. Until patched, restrict DataStage access to trusted authenticated users and monitor for service outages or unexpected file changes. Given no known exploitation but a critical 9.6 score and authenticated-only access, treat this as a high-priority routine patch rather than an emergency.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderateapprox. 1,000-10,000 enterprise installations (tens of thousands of users) - estimate; no public install counts — Cloud Pak for Data is an on-premises/private-cloud analytics platform whose enterprise installed base is generally cited in the low thousands of clients, only the 5.4.0.0 release is named as affected, and exploitation requires an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.