Executive brief
IBM DataStage is a data integration tool used to design, develop, and run data pipelines on cloud platforms. The PxXMLInput operator component is vulnerable to XML external entity (XXE) injection, which allows authenticated users to read sensitive files and extract confidential data from the system or connected storage.
Technical details
The vulnerability is an XML external entity (XXE) injection in the PxXMLInput operator of IBM DataStage running on Cloud Pak for Data 5.4.0.0. The root cause is improper restriction of XML external entity references (CWE-611), allowing the XML parser to process and resolve external entities. An authenticated remote attacker can craft a malicious XML input containing external entity declarations to read arbitrary files from the system or internal services. The attack requires authentication and network access to the DataStage service. No patch information is publicly available at this time.
Affected products
- IBM DataStage on Cloud Pak for Data 5.4.0.0
Timeline
- 2026-09-14: disclosed