Impact
The vulnerability is caused by hardcoded credentials embedded in the IBM Netezza Software source code. These credentials allow an attacker to authenticate to the container registry without authorization, enabling the retrieval of private container images that may contain proprietary code, configuration settings, and other sensitive data. The weakness is classified as CWE-522 and is rated with a CVSS score of 7.5, indicating high severity.
Affected Systems
The affected product is IBM Netezza Software version 11.3.0.3 through Interim Fix 002. The vendor provides a remediated build, version 11.3.1.3, which can be downloaded from IBM’s official software portal.
Risk and Exploitability
The CVSS score of 7.5 reflects a significant confidentiality impact, and although the EPSS score is not available, the vulnerability is likely exploitable by any actor who discovers the hardcoded credentials. The vulnerability is listed as not in the KEV catalog. Attackers could leverage the exposed credentials to authenticate remotely to the registry assuming the registry is reachable over the network; if the registry is only internally exposed, the attack vector is local but still dangerous. The risk is therefore high because the compromise can expose proprietary information without additional foothold.
OpenCVE Enrichment