CVE-2026-9744: Vulnerabilities exists in IBM Netezza Software
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Other sources
IBM Netezza Software does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Netezza Softwareto a version that resolves this vulnerability.Fixed in 11.3.1.3Patch Interim Fix 002 - Compensating control
If immediate upgrade to IBM Netezza Software 11.3.1.3 is not possible, mitigate man-in-the-middle risk while TLS certificate validation is affected (e.g., ensure TLS connections are only made to trusted endpoints using network controls such as firewall/ACL restrictions).
Event History
Frequently Asked Questions
Which deployments are affected?
IBM Netezza Software versions 11.3.0.3 through Interim Fix 002 are affected.
What must an attacker be able to do to exploit this issue?
An attacker must be able to position themselves as a man in the middle of a TLS-protected connection. No privileges or user interaction are required according to the supplied severity vector.
What is the potential impact?
An attacker may obtain sensitive information by exploiting improper TLS certificate validation. The supplied severity vector indicates an integrity impact but no confidentiality or availability impact.