ZeroHour

CVE-2026-81207

moderate

SSRF in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a server-side request forgery (CWE-918) in which any authenticated tenant — without requiring project membership or any role — can fully control the scheme, host, port, and path of an outbound HTTP fetch performed by the shared ds-canvas pod, and the fetched WSDL body is reflected verbatim in the response. An attacker triggers the flaw by issuing an authenticated request that causes the ds-canvas pod to fetch an attacker-chosen URL. Because the ds-canvas pod runs on the OpenShift overlay network, the attacker can reach co-tenant services, in-cluster Cloud Pak for Data APIs, and link-local (169.254.x.x) addresses, and the response reflection makes theft of sensitive data such as in-cluster API responses and secrets directly possible, with only minor integrity impact from GET-only side effects. Affected are organizations running DataStage on Cloud Pak for Data 5.4.0.0. No public proof-of-concept exists and the flaw is not in CISA KEV, so no exploitation is currently known.

What to do: Check IBM's security bulletin (CNA: [email protected]) for a fixed DataStage/Cloud Pak for Data release beyond 5.4.0.0 and upgrade when published. As interim mitigation, restrict network egress from the ds-canvas pod (OpenShift NetworkPolicy) so it cannot reach co-tenant workloads, in-cluster CP4D API endpoints, or link-local addresses, and consider limiting which authenticated tenants can trigger the WSDL fetch. Monitor ds-canvas egress logs for requests to unexpected hosts, unusual schemes/ports, or 169.254.x.x destinations, and audit in-cluster API tokens reachable from that pod.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderate≈1,000–10,000 enterprise deployments of DataStage on Cloud Pak for Data 5.4.0.0 (estimated) — Cloud Pak for Data is sold primarily as an enterprise self-managed deployment, and DataStage is one of its widely licensed services, so the install base is plausibly in the low thousands of deployments; no public internet-exposure scan or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.