CVE-2026-9745: Vulnerabilities exists in IBM Netezza Software
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.
Other sources
IBM Netezza Software has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Netezza Softwareto a version that resolves this vulnerability.Fixed in 11.3.1.3
Event History
Frequently Asked Questions
What conditions are needed for exploitation?
An attacker would need to control an unintended S3 bucket that can receive redirected application requests. Exploitation depends on a misconfiguration or an S3 bucket naming collision that causes Netezza operations to target that attacker-controlled bucket.
What security impact could redirected requests have?
The published vector indicates low confidentiality and low integrity impact, with no availability impact. Requests sent to an unintended bucket could expose or alter data handled through those operations.
Which deployments are known to be affected?
IBM Netezza Software version 11.3.0.3 through Interim Fix 002 is identified as affected. The provided information does not state whether earlier versions, later fixes, or default configurations are affected.
How can administrators determine whether their environment is exposed?
Review affected Netezza S3-integrated operations for use of the ExpectedBucketOwner parameter and identify any bucket configuration or naming conditions that could redirect requests. The provided information does not include a detection signature or log indicator.