IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7284359 | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-09-03 21:17
Updated : 2026-09-10 20:02
NVD link : CVE-2026-9745
Mitre link : CVE-2026-9745
CVE.ORG link : CVE-2026-9745
JSON object : View
Products Affected
ibm
- netezza_performance_server
CWE
CWE-283
Unverified Ownership
