CVE-2026-82092: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or later - Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Patch 5.4 patch 5
Event History
Frequently Asked Questions
Which deployments are identified as affected?
The provided information identifies IBM DataStage on Cloud Pak for Data version 5.4.0.0 as affected.
What access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable, but the attacker must be authenticated. No user interaction is required.
What is the potential impact of successful exploitation?
Successful exploitation could allow an authenticated remote attacker to obtain sensitive information through absolute-path traversal.