CVE-2026-9036: Vulnerabilities exists in IBM Netezza Software
Published Aug 20, 2026
·Updated
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Affected Software
3 affected components
IBM Netezza Software>=11.3.0.3<=Interim Fix 002
IBM Netezza Software<=11.3.0.3-IF2
IBM Netezza Performance Server<11.3.1.3
Remediation
Information
IBM strongly recommends addressing the vulnerability now.
Fixed Version
Remediation/Fixes: 11.3.1.3
IBM Netezza Software
Available from https://w3.ibm.com/w3publisher/software-downloads
Patch Available
Event History
Aug 20, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
Affected Software
Sep 3, 2026
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What conditions must an attacker meet to exploit this issue?
An attacker must be able to position themselves as a man in the middle on a network connection involving the affected software. The attack does not require privileges or user interaction, but CVSS rates attack complexity as high.
2
What is the likely impact of successful exploitation?
A successful man-in-the-middle attack could allow an attacker to obtain sensitive information. The stated impact is confidentiality loss; integrity and availability impacts are not identified.
3
Which releases are identified as affected?
IBM Netezza Software 11.3.0.3 through Interim Fix 002 is identified as affected.