Impact
This vulnerability is an improper TLS certificate validation weakness, categorized as CWE‑297. IBM Netezza Software 11.3.0.3 through interim fix 002 does not correctly validate server certificates. The flaw permits an attacker to impersonate the server with a forged or self‑signed certificate, leading to interception or tampering of encrypted traffic. Because the weakness affects only confidentiality and requires no privileged access, the vulnerability primarily leads to data leakage rather than full system compromise, as reflected by the CVSS score of 5.3.
Affected Systems
IBM Netezza Software installations that are running version 11.3.0.3, any later interim security fixes up to interim fix 002, and any deployments that have applied interim fix 002 without upgrading to the fixed version 11.3.1.3 are affected. The flaw is present in both the base release 11.3.0.3 and the interim security fix 002 until the patch 11.3.1.3 is deployed.
Risk and Exploitability
The likely attack vector is a network‑based position that allows the attacker to interpose between a client and the Netezza instance and present a self‑signed or otherwise invalid TLS certificate. No privileged access or authentication is required; any entity capable of traffic interception can exploit the flaw. The vulnerability is not listed in the CISA KEV catalog, and EPSS data is unavailable, suggesting uncertainty around exploitation frequency. Under typical conditions the risk is moderate, but sustained interception could lead to significant data exposure.
OpenCVE Enrichment