Executive brief
IBM DataStage is a data integration tool used within Cloud Pak for Data to manage data pipelines and transformations. A remote authenticated attacker can manipulate runtime caches through an insecure direct object reference vulnerability, causing the service to become unavailable and disrupting data processing operations.
Technical details
The vulnerability is an insecure direct object reference (IDOR) in IBM DataStage on Cloud Pak for Data 5.4.0.0 that allows a remote authenticated attacker to manipulate runtime caches without proper authorization checks. The attack requires valid authentication credentials but can be executed over the network without user interaction. By exploiting this IDOR, an attacker can trigger a denial of service condition, making the DataStage service unavailable. The vulnerability affects the caching mechanisms that DataStage relies on for runtime operations.
Affected products
- IBM DataStage on Cloud Pak for Data 5.4.0.0
Timeline
- 2026-09-10: disclosed