{"id":"CVE-2026-9736","title":"IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.","summary":"IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-117"],"vendor":"ibm","product":"netezza_performance_server","affected":["netezza_performance_server < 11.3.1.3"],"patched":["netezza_performance_server 11.3.1.3"],"published":"2026-09-03","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:35:30.600","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9736","references":[{"url":"https://www.ibm.com/support/pages/node/7284359","label":"psirt@us.ibm.com"}],"tags":["nvd"],"epss":0.00171,"epssPercentile":0.0684,"ingestedAt":"2026-09-05T21:45:14.934Z","slug":"CVE-2026-9736","body":"## Overview\n\nIBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.\n\n## Affected\n\n- `netezza_performance_server < 11.3.1.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `netezza_performance_server 11.3.1.3`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}