Impact
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows a remote authenticated attacker to use XML external entity injection in the PxXMLInput operator to read confidential data that should be inaccessible, potentially exposing sensitive business information.
Affected Systems
Affected system is IBM DataStage on Cloud Pak for Data version 5.4.0.0, which is distributed as part of the IBM Cloud Pak for Data suite.
Risk and Exploitability
The vulnerability scored 7.7 on CVSS, indicating moderate to high severity. EPSS is not available, and the issue is not listed in the CISA KEV catalog. The least‑privilege requirement means the attacker must first obtain authenticated access to the environment. Once authenticated, exploitation can be performed remotely via a crafted XML input, allowing the attacker to exfiltrate internal data.
OpenCVE Enrichment