CVE-2026-81549

9.6

IBM · DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a Server Side Request Forgery flaw due to improper validation of the X-Forwarded-Proto header, allowing sensitive information disclosure.

Executive summary

A critical Server Side Request Forgery vulnerability in IBM DataStage on Cloud Pak for Data could allow an authenticated attacker to access sensitive information.

Vulnerability

This vulnerability is categorized as CWE-918: Server Side Request Forgery (SSRF). An authenticated remote attacker can manipulate the X-Forwarded-Proto header to bypass security controls and obtain sensitive data from the environment.

Business impact

The vulnerability carries a CVSS score of 9.6, reflecting the potential for significant data compromise within the Cloud Pak for Data environment. Successful exploitation could lead to unauthorized access to internal resources or sensitive configuration data, potentially resulting in a total compromise of the affected instance's data integrity and confidentiality.

Remediation

Immediate Action: Upgrade IBM DataStage on Cloud Pak for Data to version 5.4 patch 7 or later as per the official IBM support documentation.

Proactive Monitoring: Review web server and application access logs for unusual patterns involving the X-Forwarded-Proto header or unexpected outbound requests originating from the DataStage service.

Compensating Controls: Implement strict egress filtering on the network and configure Web Application Firewalls to inspect and sanitize HTTP headers, specifically blocking or normalizing unexpected X-Forwarded-Proto values.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the critical severity rating and the potential for total impact on data confidentiality, administrators should prioritize this update immediately. Ensure all systems running DataStage on Cloud Pak for Data 5.4.0.0 are patched to the recommended version to eliminate the underlying SSRF mechanism.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources