Description
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.
Published: 2026-09-03
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in IBM Netezza Software versions 11.3.0.3 through Interim Fix 002. Operations that interact with S3 buckets omit validation of bucket ownership by not using the ExpectedBucketOwner parameter. An attacker who can control or create an S3 bucket with the same name as a legitimate one can cause the application to redirect its requests to the attacker‑controlled bucket, potentially exposing sensitive data.

Affected Systems

IBM Netezza Software, versions 11.3.0.3 to 11.3.1.3, including Interim Fix 002. The affected vendor is IBM.

Risk and Exploitability

The CVSS score is 6.5 and the EPSS score is not available. The vulnerability is not listed in CISA KEV. The likely attack vector is remote network; an attacker who can create a bucket with a colliding name can redirect application requests. The risk is moderate to high for systems that rely on external S3 buckets, as it can lead to data compromise.

Generated by OpenCVE AI on September 3, 2026 at 21:52 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Fixed Version Remediation/Fixes: 11.3.1.3 IBM Netezza Software Available from https://w3.ibm.com/w3publisher/software-downloads


OpenCVE Recommended Actions

  • Download and apply the IBM Netezza Software Interim Fix 002 (version 11.3.1.3) immediately.
  • Configure all S3 interactions in the application to specify the ExpectedBucketOwner parameter or enforce strict bucket policies that validate ownership.
  • Review bucket naming conventions and policies to prevent collisions with legitimate bucket names and restrict public access to buckets exposed by Netezza.
  • Monitor S3 access logs for anomalous request patterns that could indicate abuse of bucket ownership validation.

Generated by OpenCVE AI on September 3, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.
Title Vulnerabilities exists in IBM Netezza Software
First Time appeared Ibm
Ibm netezza Software
Weaknesses CWE-283
CPEs cpe:2.3:a:ibm:netezza_software:11.3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:netezza_software:interim:interim_fix_002:*:*:*:*:*:*
Vendors & Products Ibm
Ibm netezza Software
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Netezza Software
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-03T20:41:34.012Z

Reserved: 2026-05-27T17:40:47.125Z

Link: CVE-2026-9745

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T21:17:24.797

Modified: 2026-09-03T21:17:24.797

Link: CVE-2026-9745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T22:00:13Z

Weaknesses