CVE-2026-81549: IBM DataStage on Cloud Pak for Data vulnerability
Published Sep 21, 2026
·Updated
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.
Affected Software
1 affected componentFixes available
IBM DataStage on Cloud Pak for Data<=5.4.0.0
Event History
Sep 21, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
An attacker must be remotely authenticated. The available information does not indicate that unauthenticated users can exploit it.
2
What is the potential impact of successful exploitation?
A successful attacker could obtain sensitive information. The provided information does not identify the specific data that could be exposed.
3
What component or input is involved in the issue?
The issue is related to improper validation of the X-Forwarded-Proto HTTP header in DataStage on Cloud Pak for Data.