IBM DataStage for Cloud Pak for Data 5.4.0.0 允许任何经过身份验证的租户(无需项目成员资格或角色)完全控制从共享基础设施 Pod 发出的出站请求的目标 schema/主机/端口/路径,并且 WSDL 请求体被原样返回给调用者。ds-canvas Pod 位于 OpenShift 叠加层,可访问同租户服务、集群内 CP4D API 以及链路本地地址。影响范围:Changed(变更),机密性:高(响应反射),完整性:低(仅 GET 请求的副作用)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | DataStage on Cloud Pak for Data | 5.4.0.0 |
cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81204 | 9.8 CRITICAL | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-79724 | 9.8 CRITICAL | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-85025 | 9.8 CRITICAL | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-78573 | 9.8 CRITICAL | IBM ContextForge MCP Gateway is affected by use of default credentials |
| CVE-2026-82100 | 9.6 CRITICAL | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-82107 | 9.6 CRITICAL | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-80424 | 9.1 CRITICAL | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-19646 | 9.1 CRITICAL | Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool a |
| CVE-2026-81554 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-81940 | 8.8 HIGH | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-81211 | 8.8 HIGH | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-82095 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-82097 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-82092 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-81550 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-82098 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-82099 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-81941 | 8.8 HIGH | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-78575 | 8.8 HIGH | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-81551 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
Showing top 20 of 49 CVEs. View all on vendor page → →
No comments yet