CVE-2026-9041: Path Traversal
IBM Netezza Software could allow a remote attacker to access unauthorized resources due to improper validation of user-supplied input in server-side requests. A path traversal server-side request forgery (SSRF) vulnerability exists where an attacker can manipulate the path component of a URL in server-side requests, allowing access to unintended internal endpoints or sensitive data.
Affected Software
Event History
Frequently Asked Questions
What access would an attacker need to exploit this issue?
The issue is described as remotely exploitable through manipulation of the path component of a URL used in server-side requests. The provided information does not state whether authentication or any particular application feature is required.
What resources could be exposed?
An attacker may be able to make the server access unintended internal endpoints or sensitive data. The provided information does not identify specific endpoints, services, or data types.