CVE-2026-16468: DataStage on Cloud Pak for Data has several vulnerabilities
DataStage on Cloud Pak for Data can allow a man-in-the-middle attacker to present a forged TLS certificate, intercept the connection, and capture the IAM bearer Authorization header automatically attached by the session adapter. The captured token grants full platform-scope tenant API access, enabling the attacker to read and manipulate the victim's DataStage projects, flows, assets, and pipeline definitions. This is client-side SDK code running on the user's own machine, so exploitation requires an external network interceptor rather than a co-tenant in the shared cluster.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to OS command injection.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 7
Event History
Frequently Asked Questions
Who is realistically exposed to the TLS interception issue?
Users running the affected client-side SDK code on their own machines are exposed when an external attacker can intercept their network connection. A co-tenant in the shared Cloud Pak for Data cluster is not sufficient by itself.
What does an attacker need to capture a tenant API token through this issue?
The attacker needs to act as a man-in-the-middle and present a forged TLS certificate. The session adapter automatically attaches the IAM bearer Authorization header, which can then be captured.
What could an attacker do with a captured IAM bearer token?
The token grants full platform-scope tenant API access. It can be used to read and manipulate the victim's DataStage projects, flows, assets, and pipeline definitions.
What access is required for the command-injection issue?
The command-injection issue is described as exploitable by a remote authenticated attacker. The provided data identifies IBM DataStage on Cloud Pak for Data version 5.4.0.0 in connection with this issue.