Executive brief
IBM Netezza Performance Server Replication Services, a tool used for data synchronization across database systems, contains a vulnerability that allows a user with low-level access to gain full administrative (root) control. An attacker who has already gained a foothold on the system can use this flaw to take over the entire server, modify or delete critical data, and install persistent backdoors. This could lead to a complete loss of data confidentiality and system availability.
Technical details
A privilege escalation vulnerability exists in IBM Netezza Performance Server Replication Services versions 3.0.2.0 through 3.0.5.0 due to execution with unnecessary privileges (CWE-250). A local attacker with low-privileged access can exploit this flaw to execute commands with root authority. Successful exploitation allows the attacker to obtain a root shell, change the root password, and modify or delete system-wide files. This leads to a total compromise of the host's confidentiality, integrity, and availability. IBM has released version 3.0.5.1 to address this vulnerability.
Affected products
- IBM Netezza Performance Server Replication Services 3.0.2.0 - 3.0.5.0
Timeline
- 2026-05-07: advisory: Initial publication by IBM
- 2026-05-27: disclosed: NVD publication date