IBMCVE-2026-9744
IBM Netezza Software: information disclosure
Medium5.3CVE-2026-9744 · Published Sep 3, 2026 · updated Sep 10, 2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Netezza Software Product | >= 11.3.0.3, <= Interim Fix 002 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-297
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 3 | IBM Netezza Software: information disclosure | High7.5 | No fix yet |
| Sep 3 | IBM Netezza Software: information disclosure | Medium5.9 | No fix yet |
| Sep 3 | IBM Netezza Software: unauthorized user could inject data into log messages | Medium5.3 | No fix yet |
| Sep 3 | IBM Netezza Software: remote attacker could exploit misconfigurations or naming | Medium6.5 | No fix yet |
| Sep 3 | IBM Qiskit SDK: denial of service | Medium6.2 | No fix yet |
| Sep 2 | Scoped admin OAuth DCR endpoints ignore token_teams restrictions and expose global registered clients | Medium6.4 | v1.0.8 |