Impact
The vulnerability resides in IBM Netezza Software versions 11.3.0.3 through Interim Fix 002. Operations that interact with S3 buckets omit validation of bucket ownership by not using the ExpectedBucketOwner parameter. An attacker who can control or create an S3 bucket with the same name as a legitimate one can cause the application to redirect its requests to the attacker‑controlled bucket, potentially exposing sensitive data.
Affected Systems
IBM Netezza Software, versions 11.3.0.3 to 11.3.1.3, including Interim Fix 002. The affected vendor is IBM.
Risk and Exploitability
The CVSS score is 6.5 and the EPSS score is not available. The vulnerability is not listed in CISA KEV. The likely attack vector is remote network; an attacker who can create a bucket with a colliding name can redirect application requests. The risk is moderate to high for systems that rely on external S3 buckets, as it can lead to data compromise.
OpenCVE Enrichment