Unvalidated Bucket Ownership in IBM Netezza Software
CVE-2026-9745
6.5MEDIUM
What is CVE-2026-9745?
IBM Netezza Software versions 11.3.0.3 and Interim Fix 002 lack proper validation of bucket ownership when using the ExpectedBucketOwner parameter. This vulnerability could allow a remote attacker to leverage misconfigurations or naming conflicts to reroute application requests to unintended S3 buckets under their control, potentially compromising sensitive data and application functionality.
Affected Version(s)
Netezza Software 11.3.0.3