{"id":"CVE-2026-9745","title":"IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter","summary":"IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations o…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-283"],"vendor":"ibm","product":"netezza_performance_server","affected":["netezza_performance_server < 11.3.1.3"],"patched":["netezza_performance_server 11.3.1.3"],"published":"2026-09-03","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:02:25.363","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9745","references":[{"url":"https://www.ibm.com/support/pages/node/7284359","label":"psirt@us.ibm.com"}],"tags":["nvd"],"epss":0.00194,"epssPercentile":0.09369,"ingestedAt":"2026-09-08T15:33:26.959Z","slug":"CVE-2026-9745","body":"## Overview\n\nIBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.\n\n## Affected\n\n- `netezza_performance_server < 11.3.1.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `netezza_performance_server 11.3.1.3`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}