CVE-2026-8862: Vulnerabilities exists in IBM Netezza Software
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information.
Other sources
IBM Netezza Software has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Netezza Softwareto a version that resolves this vulnerability.Fixed in 11.3.1.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access to the affected container registry and the hardcoded credentials available in the application source code. No prior authentication or user interaction is required.
What could an attacker access?
The exposed secret can allow an attacker to pull private container images from the registry. Those images may disclose proprietary code, configuration details, and other sensitive information.
Which deployments are affected?
IBM Netezza Software version 11.3.0.3 through Interim Fix 002 is identified as affected. The provided information does not state whether other versions or configurations are affected.