IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used to impersonate other users in the system.
History

Fri, 20 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:*:*:*:*:*:*:*:*

Thu, 19 Feb 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 17 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used to impersonate other users in the system.
Title DataStage on Cloud Pak for Data is vulnerable to sensitive information leaks due to HTTP processing
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-497
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.3.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-02-17T20:17:24.149Z

Updated: 2026-02-19T04:55:49.175Z

Reserved: 2025-11-25T20:34:37.353Z

Link: CVE-2025-13691

cve-icon Vulnrichment

Updated: 2026-02-18T18:27:27.742Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-17T21:22:13.900

Modified: 2026-02-20T21:03:01.560

Link: CVE-2025-13691

cve-icon Redhat

No data.