Impact
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a server‑side request forgery flaw that permits a remote authenticated attacker to trigger arbitrary code execution. The malicious request is sent from within the application to internal services, leveraging the authenticated context to bypass typical network restrictions. Successful exploitation would give the attacker full control over the system, jeopardizing confidentiality, integrity, and availability of data and services.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0. Upgrading to patch 5 or later replaces the vulnerable component.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity and the lack of a publicly known exploit URL suggests a moderate to low exploitation probability. The attack requires valid authentication within the application, indicating an insider or compromised user scenario. The vulnerability is not listed in the CISA KEV catalog, and the EPSS score is not available. Based on the description, the likely attack vector is an authenticated SSRF request originating from the application’s internal interfaces. The impact of a successful exploit would be complete code execution, making this a critical risk for systems that have not applied the recommended patch.
OpenCVE Enrichment