Executive brief
IBM DataStage is a data integration and pipeline tool used to process and manage enterprise data flows. This vulnerability allows any authenticated user of the platform to perform Server-Side Request Forgery (SSRF) attacks, enabling them to make unauthorized outbound requests from shared infrastructure to internal services, co-tenant systems, or network endpoints, potentially exposing sensitive information through response reflection and gaining unauthorized access to internal systems.
Technical details
The vulnerability is a Server-Side Request Forgery (CWE-918) in the ds-canvas pod component of DataStage on Cloud Pak for Data. An authenticated attacker with no project membership or role can fully control the scheme, host, port, and path of outbound HTTP fetch requests originating from a shared-infrastructure pod. The WSDL response body is reflected verbatim back to the caller. The ds-canvas pod runs on the OpenShift overlay network with access to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Attack requires network reachability and authentication to the platform. An attacker can perform reconnaissance of internal infrastructure, access internal APIs, and exfiltrate sensitive data from co-tenant systems. This vulnerability has a scope change (crossing trust boundaries) and high confidentiality impact due to response reflection.
Affected products
- IBM DataStage 5.4.0.0 (on Cloud Pak for Data)
Timeline
- 2026-09-10: disclosed