CVE-2026-9736: Vulnerabilities exists in IBM Netezza Software
IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Other sources
IBM Netezza Software could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Netezza Softwareto a version that resolves this vulnerability.Fixed in 11.3.1.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthorized user can exploit it remotely; the vector is network-accessible and requires no privileges or user interaction.
What security impact is documented?
The documented impact is injection of data into log messages. The provided severity vector indicates integrity impact only, with no stated confidentiality or availability impact.
Which releases are identified as affected?
IBM Netezza Software 11.3.0.3 through Interim Fix 002 is identified as affected.