IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.
Advisories
No advisories yet.
Fixes
Solution
IBM strongly recommends addressing the vulnerability now. Fixed Version Remediation/Fixes: 11.3.1.3 IBM Netezza Software Available from https://w3.ibm.com/w3publisher/software-downloads
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7284359 |
|
History
Thu, 03 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control. | |
| Title | Vulnerabilities exists in IBM Netezza Software | |
| First Time appeared |
Ibm
Ibm netezza Software |
|
| Weaknesses | CWE-283 | |
| CPEs | cpe:2.3:a:ibm:netezza_software:11.3.0.3:*:*:*:*:*:*:* cpe:2.3:a:ibm:netezza_software:interim:interim_fix_002:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm netezza Software |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-03T20:41:34.012Z
Reserved: 2026-05-27T17:40:47.125Z
Link: CVE-2026-9745
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses