CVE-2026-9745
Received Received - Intake

IBM Netezza S3 Bucket Ownership Validation Flaw

Vulnerability report for CVE-2026-9745, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: IBM Corporation

Description

IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm netezza_software 11.3.0.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-283 The product does not properly verify that a critical resource is owned by the proper entity.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Netezza Software versions 11.3.0.3 through Interim Fix 002 have a flaw where operations do not validate bucket ownership using the ExpectedBucketOwner parameter. This allows attackers to exploit misconfigurations or naming conflicts to redirect requests to an attacker-controlled S3 bucket.

Detection Guidance

Check IBM Netezza Software logs for unexpected S3 bucket access or misconfigurations. Review network traffic for requests to unrecognized S3 endpoints. Validate bucket ownership settings in application configurations.

Impact Analysis

An attacker could intercept or manipulate data by redirecting requests to their own S3 bucket. This may lead to unauthorized access, data leakage, or tampering with sensitive information processed by the affected IBM Netezza Software.

Compliance Impact

This vulnerability could violate data integrity and confidentiality requirements under GDPR and HIPAA. Unauthorized access or data tampering may result in non-compliance, leading to legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Apply Interim Fix 002 or later. Ensure ExpectedBucketOwner parameter is properly configured in all S3 operations. Audit bucket ownership and access controls. Restrict S3 bucket permissions to least privilege.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9745. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart