CVE-2026-81551: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4.0.0Patch 5 - Upgrade
Upgrade
DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or later
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker must be remotely authenticated. No user interaction is required, and the attack complexity is low.
What could an attacker do if exploitation succeeds?
The attacker could use path traversal to arbitrarily write to or delete files on shared storage. This can affect confidentiality, integrity, and availability.
Which version is identified as affected?
IBM DataStage on Cloud Pak for Data 5.4.0.0 is identified as affected in the provided information.