Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a server‑side request forgery flaw that permits a remote authenticated attacker to trigger arbitrary code execution. The malicious request is sent from within the application to internal services, leveraging the authenticated context to bypass typical network restrictions. Successful exploitation would give the attacker full control over the system, jeopardizing confidentiality, integrity, and availability of data and services.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0. Upgrading to patch 5 or later replaces the vulnerable component.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity and the lack of a publicly known exploit URL suggests a moderate to low exploitation probability. The attack requires valid authentication within the application, indicating an insider or compromised user scenario. The vulnerability is not listed in the CISA KEV catalog, and the EPSS score is not available. Based on the description, the likely attack vector is an authenticated SSRF request originating from the application’s internal interfaces. The impact of a successful exploit would be complete code execution, making this a critical risk for systems that have not applied the recommended patch.

Generated by OpenCVE AI on September 11, 2026 at 05:08 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade IBM DataStage on Cloud Pak for Data to patch 5 or later as described in IBM’s documentation.
  • Follow the IBM support instructions at https://www.ibm.com/docs/en/software-hub/5.4.x to apply the patch securely.
  • Implement strict network segmentation and restrict outgoing requests from authenticated accounts to minimize the potential impact of SSRF attacks.

Generated by OpenCVE AI on September 11, 2026 at 05:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0:*:*:*:*:*:*:*

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T15:41:31.238Z

Reserved: 2026-08-28T04:44:28.170Z

Link: CVE-2026-82097

cve-icon Vulnrichment

Updated: 2026-09-14T15:39:40.793Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:03.650

Modified: 2026-09-16T00:40:49.307

Link: CVE-2026-82097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:30:11Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)