CVE-2026-82097: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or later
Event History
Frequently Asked Questions
Which deployments are identified as affected?
The provided advisory information specifically identifies IBM DataStage on Cloud Pak for Data version 5.4.0.0.
What access does an attacker need to exploit this issue?
An attacker must be remotely reachable and authenticated. No user interaction is required, and the stated impact includes arbitrary code execution with high confidentiality, integrity, and availability impact.