CVE-2026-9036: Vulnerabilities exists in IBM Netezza Software
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Netezza Softwareto a version that resolves this vulnerability.Fixed in 11.3.1.3
Event History
Frequently Asked Questions
What conditions must an attacker meet to exploit this issue?
An attacker must be able to position themselves as a man in the middle on a network connection involving the affected software. The attack does not require privileges or user interaction, but CVSS rates attack complexity as high.
What is the likely impact of successful exploitation?
A successful man-in-the-middle attack could allow an attacker to obtain sensitive information. The stated impact is confidentiality loss; integrity and availability impacts are not identified.
Which releases are identified as affected?
IBM Netezza Software 11.3.0.3 through Interim Fix 002 is identified as affected.