Executive brief
IBM DataStage is a data integration tool used within Cloud Pak for Data to design and run enterprise data pipelines. An authenticated attacker can exploit a path traversal vulnerability during archive extraction to create arbitrary files on the system, potentially allowing them to overwrite critical files, inject malicious code, or compromise the integrity of the data platform and its stored information.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in the archive extraction functionality of DataStage that fails to properly validate file paths. An authenticated attacker can exploit this by crafting a malicious archive file containing path traversal sequences (e.g., "../") to cause files to be extracted outside the intended directory. The vulnerability requires valid user authentication and is exploitable over the network with no user interaction required beyond triggering the archive extraction process. Successful exploitation allows an attacker to create arbitrary files anywhere on the shared storage, potentially leading to code execution, configuration tampering, or denial of service. No patch availability information was provided in the advisory.
Affected products
- IBM DataStage on Cloud Pak for Data 5.4.0.0
Timeline
- 2026-09-10: disclosed