Impact
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows an authenticated tenant that is not a member of any project to specify the scheme, host, port, and path of an outbound fetch that originates from a shared‑infrastructure pod. The response, including the WSDL body, is returned verbatim to the caller, exposing internal endpoints and enabling data leakage. This flaw permits a tenant to trigger server‑side requests and potentially reach resources that should be isolated, effectively turning the data stage service into an SSRF vector. The impact includes high confidentiality risk from information disclosure and is a potential gateway for further attacks, but it does not provide arbitrary code execution or guarantee integrity damage.
Affected Systems
IBM DataStage on Cloud Pak for Data, version 5.4.0.0.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity, and the absence of an EPSS score suggests that a public exploit is not yet known or recorded. The vulnerability is not listed in CISA’s KEV catalog, implying that it is not a publicly exploited or known threat at the time of assessment. The likely attack vector is through any authenticated user account within the tenant, regardless of project affiliation. An attacker could craft a request that triggers an outbound fetch to internal services, gaining access to data from those endpoints. The exploitation requires no special privileges beyond tenant authentication, making successful attacks readily achievable on affected environments.
OpenCVE Enrichment