CVE-2026-80380: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
DataStage on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or later
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue is a cross-site request forgery weakness, so exploitation would require causing a user of DataStage on Cloud Pak for Data to submit an unintended request. The provided data does not specify the required user privileges or affected actions.
Is a default deployment affected?
The provided data identifies IBM DataStage on Cloud Pak for Data as affected, but it does not state whether the vulnerability applies to default configurations or only particular deployments.
What can be done if patching is not immediately possible?
The provided data does not include mitigations or workaround guidance. Consult the referenced IBM support advisory for vendor remediation information.