Impact
This vulnerability allows an unauthorized user to inject data into log messages due to improper neutralization of special elements when writing to logs, a weakness defined by CWE‑117. The injected data can change or corrupt audit logs, obscure true activity, or lead to misleading information presented to administrators, thereby facilitating further attacks or covering tracks.
Affected Systems
IBM Netezza Software is affected, specifically version 11.3.0.3 and earlier interim fixed releases before 002. The vendor recommends applying the security fix found in version 11.3.1.3. All installations running 11.3.0.3 or earlier without the interim patch are at risk.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity, and the risk is limited to log manipulation, not immediate remote code execution. Because EPSS is not available, the likelihood of exploitation is uncertain, and the vulnerability is not currently listed in the CISA KEV catalog. A non‑privileged or malicious user who can submit data that is logged can trigger the injection, so systems that expose loggable input without proper validation are vulnerable.
OpenCVE Enrichment