CVE-2026-81207
moderateSSRF in IBM DataStage on Cloud Pak for Data 5.4.0.0
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a server-side request forgery (CWE-918) in which any authenticated tenant — without requiring project membership or any role — can fully control the scheme, host, port, and path of an outbound HTTP fetch performed by the shared ds-canvas pod, and the fetched WSDL body is reflected verbatim in the response. An attacker triggers the flaw by issuing an authenticated request that causes the ds-canvas pod to fetch an attacker-chosen URL. Because the ds-canvas pod runs on the OpenShift overlay network, the attacker can reach co-tenant services, in-cluster Cloud Pak for Data APIs, and link-local (169.254.x.x) addresses, and the response reflection makes theft of sensitive data such as in-cluster API responses and secrets directly possible, with only minor integrity impact from GET-only side effects. Affected are organizations running DataStage on Cloud Pak for Data 5.4.0.0. No public proof-of-concept exists and the flaw is not in CISA KEV, so no exploitation is currently known.
What to do: Check IBM's security bulletin (CNA: [email protected]) for a fixed DataStage/Cloud Pak for Data release beyond 5.4.0.0 and upgrade when published. As interim mitigation, restrict network egress from the ds-canvas pod (OpenShift NetworkPolicy) so it cannot reach co-tenant workloads, in-cluster CP4D API endpoints, or link-local addresses, and consider limiting which authenticated tenants can trigger the WSDL fetch. Monitor ds-canvas egress logs for requests to unexpected hosts, unusual schemes/ports, or 169.254.x.x destinations, and audit in-cluster API tokens reachable from that pod.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.