Impact
The vulnerability is a cross‑site request forgery flaw that permits a remote attacker, by forcing a victim’s browser to send a malicious request, to trigger privileged operations within IBM DataStage on Cloud Pak for Data. The attacker can perform any action authorized for the victim’s session, such as modifying data, starting or stopping jobs, or changing configuration settings, thereby compromising the integrity of the platform.
Affected Systems
Affected is IBM DataStage on Cloud Pak for Data version 5.4.0.0. IBM recommends upgrading to the 5.4 release, patch 5 or later, which includes the CSRF mitigation. The product is the DataStage module within Cloud Pak for Data.
Risk and Exploitability
The CVSS score of 7.1 signifies high severity. No EPSS data is available, so no quantified exploit probability exists, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploitation. The likely attack vector is web‑based, where an authenticated user’s browser can be compelled to submit state‑changing requests to the application. Without mitigation, a threat actor could carry out unauthorized actions using the victim’s privileges.
OpenCVE Enrichment