CVE-2026-82107: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or laterPatch 5.4 patch 5
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated. The provided information does not indicate that unauthenticated users can exploit it.
Which deployment version is identified as affected?
IBM DataStage on Cloud Pak for Data 5.4.0.0 is identified as affected.
What could a successful attacker do?
An authenticated remote attacker could obtain sensitive information and bypass security restrictions due to improper authentication.