IBMCVE-2026-9736
IBM Netezza Software: unauthorized user could inject data into log messages
Medium5.3CVE-2026-9736 · Published Sep 3, 2026 · updated Sep 10, 2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Netezza Software Product | >= 11.3.0.3, <= Interim Fix 002 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-117
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 3 | IBM Netezza Software: information disclosure | High7.5 | No fix yet |
| Sep 3 | IBM Netezza Software: information disclosure | Medium5.9 | No fix yet |
| Sep 3 | IBM Netezza Software: information disclosure | Medium5.3 | No fix yet |
| Sep 3 | IBM Netezza Software: remote attacker could exploit misconfigurations or naming | Medium6.5 | No fix yet |
| Sep 3 | IBM Qiskit SDK: denial of service | Medium6.2 | No fix yet |
| Sep 2 | Scoped admin OAuth DCR endpoints ignore token_teams restrictions and expose global registered clients | Medium6.4 | v1.0.8 |