ZeroHour

CVE-2026-82097

moderate

SSRF to arbitrary code execution in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage running on Cloud Pak for Data 5.4.0.0 contains a server-side request forgery (SSRF) flaw, CWE-918, that allows the application server to be coerced into issuing requests to attacker-influenced targets. A remote attacker who already holds low-privilege authenticated access to DataStage can trigger the flaw with no user interaction, and IBM states it can lead to arbitrary code execution on the server. Successful exploitation would compromise the confidentiality, integrity, and availability of the DataStage instance (CVSS 3.1: 8.8), and the SSRF primitive may also let the attacker reach other internal services from the server's network position. Only organizations running DataStage on Cloud Pak for Data version 5.4.0.0 are affected per the available advisory data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.

What to do: Verify your deployed Cloud Pak for Data release and, because only 5.4.0.0 is named in this data, consult IBM's security bulletin for the exact patched update level before upgrading. In the meantime, restrict which authenticated accounts can supply URLs or hosts to DataStage jobs and limit outbound network access from DataStage pods to reduce SSRF-to-RCE reach. Monitor IBM PSIRT advisories for the fix version and any escalation to CISA KEV.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderatelikely on the order of a few thousand enterprise Cloud Pak for Data deployments worldwide; directly internet-exposed instances likely far fewer (exact counts… — IBM publishes no install counts, but Cloud Pak for Data is deployed inside enterprise OpenShift clusters by large organizations and DataStage is among its most widely used services, so the estimate assumes only the recent 5.4.0.0 release…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.

Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.