Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
Published: 2026-09-14
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via XXE
Action: Immediate patch
AI Analysis

Impact

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows a remote authenticated attacker to use XML external entity injection in the PxXMLInput operator to read confidential data that should be inaccessible, potentially exposing sensitive business information.

Affected Systems

Affected system is IBM DataStage on Cloud Pak for Data version 5.4.0.0, which is distributed as part of the IBM Cloud Pak for Data suite.

Risk and Exploitability

The vulnerability scored 7.7 on CVSS, indicating moderate to high severity. EPSS is not available, and the issue is not listed in the CISA KEV catalog. The least‑privilege requirement means the attacker must first obtain authenticated access to the environment. Once authenticated, exploitation can be performed remotely via a crafted XML input, allowing the attacker to exfiltrate internal data.

Generated by OpenCVE AI on September 15, 2026 at 12:22 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade DataStage on Cloud Pak for Data to patch 5 or later following IBM’s documentation
  • If upgrade is not feasible, reconfigure XML parsers in the PxXMLInput operator to disable external entity resolution, preventing XXE exploitation
  • Restrict access to the PxXMLInput operator to privileged users only and monitor for anomalous access patterns

Generated by OpenCVE AI on September 15, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T20:13:30.750Z

Reserved: 2026-07-21T00:31:43.635Z

Link: CVE-2026-16432

cve-icon Vulnrichment

Updated: 2026-09-14T20:13:10.612Z

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:40.663

Modified: 2026-09-14T21:17:03.330

Link: CVE-2026-16432

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T12:30:13Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference