Impact
The vulnerability arises because IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate TLS certificates correctly, which could allow an attacker to mount a man‑in‑the‑middle attack and read or modify traffic, leading to potential disclosure of sensitive data. This flaw is a classic certificate validation weakness (CWE‑295) and does not allow arbitrary code execution but could compromise confidentiality and integrity in transit.
Affected Systems
The affected vendor is IBM and the product is Netezza Software. All installations running 11.3.0.3 up to but not including the interim fix 002 are susceptible. The remediation fixes are available in version 11.3.1.3 and can be downloaded from IBM’s software site.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate impact, but because the flaw involves intercepting network traffic, it can be quite damaging if an attacker has network visibility. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, but the attack vector is inferred to be remote over the network where TLS traffic is exchanged. Mitigation requires updating to the patched version or otherwise enforcing strict certificate verification.
OpenCVE Enrichment