Unvalidated Bucket Ownership in IBM Netezza Software
CVE-2026-9745

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
3 September 2026

What is CVE-2026-9745?

IBM Netezza Software versions 11.3.0.3 and Interim Fix 002 lack proper validation of bucket ownership when using the ExpectedBucketOwner parameter. This vulnerability could allow a remote attacker to leverage misconfigurations or naming conflicts to reroute application requests to unintended S3 buckets under their control, potentially compromising sensitive data and application functionality.

Affected Version(s)

Netezza Software 11.3.0.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.