---
id: CVE-2026-9036
title: >-
  IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or
  improperly validates TLS certificate validation, which could allow an attacker
  to obtain sensitive information using man in the middle techniques.
summary: >-
  IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or
  improperly validates TLS certificate validation, which could allow an attacker
  to obtain sensitive information using man in the middle techniques.
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-295
vendor: ibm
product: netezza_performance_server
affected:
  - netezza_performance_server < 11.3.1.3
patched:
  - netezza_performance_server 11.3.1.3
published: '2026-09-03'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T21:17:53.300'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9036'
references:
  - url: 'https://www.ibm.com/support/pages/node/7284359'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T20:38:54.215185Z'
epss: 0.00129
epssPercentile: 0.02853
ingestedAt: '2026-09-08T15:33:26.959Z'
---

## Overview

IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.

## Affected

- `netezza_performance_server < 11.3.1.3`

## Remediation

Upgrade past the affected range:

- `netezza_performance_server 11.3.1.3`
