CVE-2025-13691

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used to impersonate other users in the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7259956 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:*:*:*:*:*:*:*:*

History

20 Feb 2026, 21:03

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7259956 - () https://www.ibm.com/support/pages/node/7259956 - Vendor Advisory
First Time Ibm
Ibm datastage On Cloud Pak For Data
CPE cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:*:*:*:*:*:*:*:*

18 Feb 2026, 17:51

Type Values Removed Values Added
Summary
  • (es) IBM DataStage en Cloud Pak for Data desde 5.1.2 hasta 5.3.0 devuelve información sensible en una respuesta HTTP que podría usarse para suplantar a otros usuarios en el sistema.

17 Feb 2026, 21:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-17 21:22

Updated : 2026-02-20 21:03


NVD link : CVE-2025-13691

Mitre link : CVE-2025-13691

CVE.ORG link : CVE-2025-13691


JSON object : View

Products Affected

ibm

  • datastage_on_cloud_pak_for_data
CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere