Executive brief
IBM DataStage, a data integration and ETL (extract, transform, load) platform used to manage enterprise data pipelines, is vulnerable to cross-site request forgery (CSRF) attacks. An attacker could trick authenticated users into performing unauthorized actions such as modifying data pipelines, executing jobs, or altering configurations, potentially leading to data corruption or unauthorized data processing.
Technical details
This is a cross-site request forgery vulnerability in IBM DataStage on Cloud Pak for Data 5.4.0.0. The vulnerability allows a remote, unauthenticated attacker to craft a malicious web page or email that, when visited by an authenticated DataStage user, executes unauthorized actions on the user's behalf without their knowledge or consent. The attack requires user interaction (victim must visit the attacker-controlled page while authenticated), but no additional authentication is needed from the attacker. Successful exploitation could result in unauthorized job execution, pipeline modifications, or configuration changes. Patch availability should be confirmed via IBM security bulletins.
Affected products
- IBM DataStage 5.4.0.0
Timeline
- 2026-09-10: disclosed