CyberRota Analysis
AI-GeneratedIBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable, allowing any authenticated tenant to manipulate outbound fetch requests without requiring project membership or specific roles. This could lead to unauthorized access to sensitive data and potential data leakage, as the WSDL body is reflected verbatim to the caller. Organizations utilizing this version of IBM DataStage should prioritize immediate remediation to mitigate risks associated with this high-severity vulnerability.
Original NVD Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).