CVE-2026-9744: Vulnerabilities exists in IBM Netezza Software
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Other sources
IBM Netezza Software does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Netezza Softwareto a version that resolves this vulnerability.Fixed in 11.3.1.3
Event History
Frequently Asked Questions
Which deployments are affected?
IBM Netezza Software versions 11.3.0.3 through Interim Fix 002 are affected.
What must an attacker be able to do to exploit this issue?
An attacker must be able to position themselves as a man in the middle of a TLS-protected connection. No privileges or user interaction are required according to the supplied severity vector.
What is the potential impact?
An attacker may obtain sensitive information by exploiting improper TLS certificate validation. The supplied severity vector indicates an integrity impact but no confidentiality or availability impact.