CVE-2026-81540: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or later - Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or laterPatch 5.4 patch 5
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated to IBM DataStage on Cloud Pak for Data. The issue is particularly relevant in multi-tenant deployments because the attacker may overwrite ruleset files belonging to other tenants.
What is the impact of successful exploitation?
An authenticated attacker could use path traversal to overwrite ruleset files associated with another tenant. The provided information does not state whether files other than ruleset files can be affected.
Is an unauthenticated or default deployment affected?
The issue is described as requiring authentication. The available information does not say whether a default configuration is affected or identify affected versions.