๐Ÿ” CVE Alert

CVE-2026-9745

MEDIUM 6.5

Vulnerabilities exists in IBM Netezza Software

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.

CWE CWE-283
Vendor ibm
Product netezza software
Published Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for ibm netezza software

Be the first to know when new medium vulnerabilities affecting ibm netezza software are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

IBM / Netezza Software
11.3.0.3 โ‰ค Interim Fix 002

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
ibm.com: https://www.ibm.com/support/pages/node/7284359