Executive brief
IBM DataStage is a data integration and ETL (extract-transform-load) tool used to process and manage business data in enterprise environments. A path traversal vulnerability in DataStage on Cloud Pak for Data could allow an authenticated attacker to cause the service to become unavailable, disrupting critical data pipeline operations and impacting business-dependent analytics and reporting.
Technical details
A path traversal vulnerability (CWE-22) in IBM DataStage on Cloud Pak for Data allows a remote authenticated attacker to craft malicious input that traverses directory boundaries and access unintended files or directories, resulting in denial of service. The vulnerability requires valid authentication credentials and network access to the DataStage service. By exploiting the improper validation of file paths, an attacker can trigger a condition that crashes or stops the service. The vulnerability affects version 5.4.0.0 and patches or fixes should be obtained from IBM's support channels.
Affected products
- IBM DataStage 5.4.0.0
Timeline
- 2026-09-10: disclosed