Executive brief
IBM Netezza Software contains hardcoded credentials embedded in its source code that allow unauthorized access to the container registry. An attacker exploiting this flaw can pull private container images, potentially exposing proprietary code, configuration details, and other sensitive business information stored within those images.
Technical details
The vulnerability is a credential exposure flaw where sensitive authentication credentials are hardcoded in the IBM Netezza Software application source code. This allows attackers to authenticate to the container registry without authorization. The exposed credentials enable pulling of private container images, which may contain proprietary code, configuration secrets, and sensitive data. The vulnerability affects Netezza Software versions 11.3.0.3 through Interim Fix 002, and is fixed in version 11.3.1.3. Attack requires network access to the container registry but no prior authentication or user interaction.
Affected products
- IBM Netezza Software 11.3.0.3 through Interim Fix 002
Timeline
- 2026-09-03: disclosed
- 2026: patched: Fixed in version 11.3.1.3