CVE-2026-16432
nicheAuthenticated XXE in IBM DataStage (Cloud Pak for Data) 5.4.0.0 Exposes Files
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an XML external entity (XXE) injection flaw in the PxXMLInput operator, the parallel-engine component that parses XML input during ETL jobs. A remote attacker with valid (low-privilege) credentials can trigger it by supplying crafted XML containing external entity definitions that the operator resolves when the job processes the input. Because the parser follows out-of-band entity references, the attacker can read local files accessible to the DataStage engine and potentially probe internal network services (SSRF), obtaining sensitive information from the host or metadata tier. Organizations running DataStage on Cloud Pak for Data 5.4.0.0 whose users can upload or point jobs at attacker-influenced XML are affected; the CVSS 3.1 base score is 7.7 (high) with changed scope and high confidentiality impact but no integrity or availability impact. The vulnerability is not in the CISA KEV catalog, no public proof-of-concept is known, and no exploitation has been reported.
What to do: Apply the fixed release specified in IBM's security bulletin for DataStage on Cloud Pak for Data as soon as it is available, since only 5.4.0.0 is listed as affected. Until patched, restrict who can define XML input stages or supply XML sources to DataStage jobs, and validate or sanitize incoming XML to strip DTDs and external entities before processing. Monitor the DataStage engine tier for unexpected local file reads and outbound connections to internal hosts, which are telltale XXE behavior.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.