Description
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information.
Published: 2026-09-03
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is caused by hardcoded credentials embedded in the IBM Netezza Software source code. These credentials allow an attacker to authenticate to the container registry without authorization, enabling the retrieval of private container images that may contain proprietary code, configuration settings, and other sensitive data. The weakness is classified as CWE-522 and is rated with a CVSS score of 7.5, indicating high severity.

Affected Systems

The affected product is IBM Netezza Software version 11.3.0.3 through Interim Fix 002. The vendor provides a remediated build, version 11.3.1.3, which can be downloaded from IBM’s official software portal.

Risk and Exploitability

The CVSS score of 7.5 reflects a significant confidentiality impact, and although the EPSS score is not available, the vulnerability is likely exploitable by any actor who discovers the hardcoded credentials. The vulnerability is listed as not in the KEV catalog. Attackers could leverage the exposed credentials to authenticate remotely to the registry assuming the registry is reachable over the network; if the registry is only internally exposed, the attack vector is local but still dangerous. The risk is therefore high because the compromise can expose proprietary information without additional foothold.

Generated by OpenCVE AI on September 3, 2026 at 21:29 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Fixed Version Remediation/Fixes: 11.3.1.3 IBM Netezza Software Available from https://w3.ibm.com/w3publisher/software-downloads


OpenCVE Recommended Actions

  • Apply the IBM Netezza Software patch 11.3.1.3 via the IBM software download portal
  • Ensure the container registry is configured to allow access only to authorized users by disabling or restricting anonymous pull
  • Enable audit logging for registry access attempts and regularly review logs for unauthorized activity

Generated by OpenCVE AI on September 3, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information.
Title Vulnerabilities exists in IBM Netezza Software
First Time appeared Ibm
Ibm netezza Software
Weaknesses CWE-522
CPEs cpe:2.3:a:ibm:netezza_software:11.3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:netezza_software:interim:interim_fix_002:*:*:*:*:*:*
Vendors & Products Ibm
Ibm netezza Software
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Netezza Software
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-03T20:42:59.625Z

Reserved: 2026-05-18T19:27:37.883Z

Link: CVE-2026-8862

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T21:17:24.307

Modified: 2026-09-03T21:17:24.307

Link: CVE-2026-8862

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T21:30:06Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials