HIGH
CVE-2026-16432
CVSS
7.7
Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
Weakness (CWE)
CWE-611
XML External Entity (XXE)
EPSS Score
0.34%
Probability of exploitation in next 30 days
28th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.