ZeroHour

CVE-2026-16432

niche

Authenticated XXE in IBM DataStage (Cloud Pak for Data) 5.4.0.0 Exposes Files

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an XML external entity (XXE) injection flaw in the PxXMLInput operator, the parallel-engine component that parses XML input during ETL jobs. A remote attacker with valid (low-privilege) credentials can trigger it by supplying crafted XML containing external entity definitions that the operator resolves when the job processes the input. Because the parser follows out-of-band entity references, the attacker can read local files accessible to the DataStage engine and potentially probe internal network services (SSRF), obtaining sensitive information from the host or metadata tier. Organizations running DataStage on Cloud Pak for Data 5.4.0.0 whose users can upload or point jobs at attacker-influenced XML are affected; the CVSS 3.1 base score is 7.7 (high) with changed scope and high confidentiality impact but no integrity or availability impact. The vulnerability is not in the CISA KEV catalog, no public proof-of-concept is known, and no exploitation has been reported.

What to do: Apply the fixed release specified in IBM's security bulletin for DataStage on Cloud Pak for Data as soon as it is available, since only 5.4.0.0 is listed as affected. Until patched, restrict who can define XML input stages or supply XML sources to DataStage jobs, and validate or sanitize incoming XML to strip DTDs and external entities before processing. Monitor the DataStage engine tier for unexpected local file reads and outbound connections to internal hosts, which are telltale XXE behavior.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
nichelikely low thousands of enterprise deployments worldwide; no public install counts — DataStage is commercially licensed enterprise ETL software deployed per-organization inside Cloud Pak for Data (typically on private OpenShift clusters), so there are no public active-install metrics and internet-exposed counts are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.