Description
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Published: 2026-09-03
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate TLS certificates correctly, which could allow an attacker to mount a man‑in‑the‑middle attack and read or modify traffic, leading to potential disclosure of sensitive data. This flaw is a classic certificate validation weakness (CWE‑295) and does not allow arbitrary code execution but could compromise confidentiality and integrity in transit.

Affected Systems

The affected vendor is IBM and the product is Netezza Software. All installations running 11.3.0.3 up to but not including the interim fix 002 are susceptible. The remediation fixes are available in version 11.3.1.3 and can be downloaded from IBM’s software site.

Risk and Exploitability

The CVSS base score of 5.9 indicates moderate impact, but because the flaw involves intercepting network traffic, it can be quite damaging if an attacker has network visibility. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, but the attack vector is inferred to be remote over the network where TLS traffic is exchanged. Mitigation requires updating to the patched version or otherwise enforcing strict certificate verification.

Generated by OpenCVE AI on September 3, 2026 at 22:21 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Fixed Version Remediation/Fixes: 11.3.1.3 IBM Netezza Software Available from https://w3.ibm.com/w3publisher/software-downloads


OpenCVE Recommended Actions

  • Download and install IBM Netezza Software patch 11.3.1.3 from the IBM website.
  • Reconfigure any custom trust stores to include only trusted CAs.
  • Monitor TLS traffic for anomalies and ensure clients reject invalid certificates.
  • Conduct a network scan or log review to detect any existing man‑in‑the‑middle activity, and apply network segmentation or firewall rules to restrict exposed services.

Generated by OpenCVE AI on September 3, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Title Vulnerabilities exists in IBM Netezza Software
First Time appeared Ibm
Ibm netezza Software
Weaknesses CWE-295
CPEs cpe:2.3:a:ibm:netezza_software:11.3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:netezza_software:interim:interim_fix_002:*:*:*:*:*:*
Vendors & Products Ibm
Ibm netezza Software
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Netezza Software
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-03T20:42:08.092Z

Reserved: 2026-05-19T16:54:27.268Z

Link: CVE-2026-9036

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T21:17:24.440

Modified: 2026-09-03T21:17:24.440

Link: CVE-2026-9036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T22:30:10Z

Weaknesses
  • CWE-295

    Improper Certificate Validation