---
id: CVE-2026-9736
title: >-
  IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an
  unauthorized user to inject data into log messages due to improper
  neutralization of special elements when written to log files.
summary: >-
  IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an
  unauthorized user to inject data into log messages due to improper
  neutralization of special elements when written to log files.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-117
vendor: ibm
product: netezza_performance_server
affected:
  - netezza_performance_server < 11.3.1.3
patched:
  - netezza_performance_server 11.3.1.3
published: '2026-09-03'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T20:35:30.600'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9736'
references:
  - url: 'https://www.ibm.com/support/pages/node/7284359'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00286
epssPercentile: 0.1876
ingestedAt: '2026-09-05T21:45:14.934Z'
---

## Overview

IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

## Affected

- `netezza_performance_server < 11.3.1.3`

## Remediation

Upgrade past the affected range:

- `netezza_performance_server 11.3.1.3`
