IBMCVE-2026-8862
IBM Netezza Software: information disclosure
High7.5CVE-2026-8862 · Published Sep 3, 2026 · updated Sep 10, 2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Netezza Software Product | >= 11.3.0.3, <= Interim Fix 002 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-522
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 3 | IBM Netezza Software: information disclosure | Medium5.9 | No fix yet |
| Sep 3 | IBM Netezza Software: unauthorized user could inject data into log messages | Medium5.3 | No fix yet |
| Sep 3 | IBM Netezza Software: information disclosure | Medium5.3 | No fix yet |
| Sep 3 | IBM Netezza Software: remote attacker could exploit misconfigurations or naming | Medium6.5 | No fix yet |
| Sep 3 | IBM Qiskit SDK: denial of service | Medium6.2 | No fix yet |
| Sep 2 | Scoped admin OAuth DCR endpoints ignore token_teams restrictions and expose global registered clients | Medium6.4 | v1.0.8 |