Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).
Published: 2026-09-10
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Server-side request forgery
Action: Patch Now
AI Analysis

Impact

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows an authenticated tenant that is not a member of any project to specify the scheme, host, port, and path of an outbound fetch that originates from a shared‑infrastructure pod. The response, including the WSDL body, is returned verbatim to the caller, exposing internal endpoints and enabling data leakage. This flaw permits a tenant to trigger server‑side requests and potentially reach resources that should be isolated, effectively turning the data stage service into an SSRF vector. The impact includes high confidentiality risk from information disclosure and is a potential gateway for further attacks, but it does not provide arbitrary code execution or guarantee integrity damage.

Affected Systems

IBM DataStage on Cloud Pak for Data, version 5.4.0.0.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity, and the absence of an EPSS score suggests that a public exploit is not yet known or recorded. The vulnerability is not listed in CISA’s KEV catalog, implying that it is not a publicly exploited or known threat at the time of assessment. The likely attack vector is through any authenticated user account within the tenant, regardless of project affiliation. An attacker could craft a request that triggers an outbound fetch to internal services, gaining access to data from those endpoints. The exploitation requires no special privileges beyond tenant authentication, making successful attacks readily achievable on affected environments.

Generated by OpenCVE AI on September 11, 2026 at 04:47 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0Upgrade to 5.4 patch 5 or later by following these instructions.


OpenCVE Recommended Actions

  • Upgrade DataStage on Cloud Pak for Data to 5.4 patch 5 or a newer release, following IBM’s official upgrade guide.
  • Restrict outbound fetch capabilities to authenticated users with appropriate roles or project membership, ensuring that only authorized tenants can trigger external requests.
  • Configure network policies or firewall rules to limit the shared‑infrastructure pod’s reach to internal services and expose only necessary endpoints, reducing the attack surface for SSRF.

Generated by OpenCVE AI on September 11, 2026 at 04:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0:*:*:*:*:*:*:*

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-11T13:46:24.382Z

Reserved: 2026-08-26T16:48:12.349Z

Link: CVE-2026-81207

cve-icon Vulnrichment

Updated: 2026-09-11T13:39:10.731Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:01.703

Modified: 2026-09-16T00:45:50.890

Link: CVE-2026-81207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:45:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)