Skip to content
IBMCVE-2026-9736

IBM Netezza Software: unauthorized user could inject data into log messages

Medium5.3CVE-2026-9736 · Published Sep 3, 2026 · updated Sep 10, 2026

IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

IBM advisory

Affected versions

PackageAffectedFixed in
Netezza Software
Product
>= 11.3.0.3, <= Interim Fix 002No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-117

More IBM advisories

All IBM
Advisory
IBM Netezza Software: information disclosure
High7.5Sep 3
IBM Netezza Software: information disclosure
Medium5.9Sep 3
IBM Netezza Software: information disclosure
Medium5.3Sep 3
IBM Netezza Software: remote attacker could exploit misconfigurations or naming
Medium6.5Sep 3
IBM Qiskit SDK: denial of service
Medium6.2Sep 3
Scoped admin OAuth DCR endpoints ignore token_teams restrictions and expose global registered clients
Medium6.4Sep 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.