IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.
History

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.
Title Vulnerabilities exists in IBM Netezza Software
First Time appeared Ibm
Ibm netezza Software
Weaknesses CWE-283
CPEs cpe:2.3:a:ibm:netezza_software:11.3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:netezza_software:interim:interim_fix_002:*:*:*:*:*:*
Vendors & Products Ibm
Ibm netezza Software
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-09-03T20:41:34.012Z

Updated: 2026-09-04T13:41:19.897Z

Reserved: 2026-05-27T17:40:47.125Z

Link: CVE-2026-9745

cve-icon Vulnrichment

Updated: 2026-09-04T13:28:22.271Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-03T21:17:24.797

Modified: 2026-09-08T14:17:08.940

Link: CVE-2026-9745

cve-icon Redhat

No data.