XXE Injection Vulnerability in IBM DataStage on Cloud Pak for Data
CVE-2026-16432

7.7HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 September 2026

What is CVE-2026-16432?

An XXE injection vulnerability in the PxXMLInput operator of IBM DataStage on Cloud Pak for Data 5.4.0.0 allows a remote authenticated attacker to exploit XML parsing features to access sensitive information. This security risk can lead to unauthorized disclosure of data, thereby compromising the integrity of the affected system.

Affected Version(s)

DataStage on Cloud Pak for Data 5.4.0.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.