Executive brief
IBM Netezza Software, a data warehouse and analytics platform, does not properly validate TLS certificates. An attacker positioned on the network could intercept encrypted communications between the software and servers it connects to, potentially stealing sensitive data without being detected. This allows unauthorized surveillance of database queries, credentials, and other confidential information in transit.
Technical details
The vulnerability is an improper certificate validation flaw (CWE-295) in IBM Netezza Software versions 11.3.0.3 through Interim Fix 002. The software does not properly validate or verify TLS certificates when establishing secure connections, allowing an attacker to perform man-in-the-middle (MITM) attacks over a network. An attacker does not require authentication and can intercept traffic if positioned on the network path. The attacker can read sensitive data transmitted over these connections. The vulnerability is fixed in version 11.3.1.3 or later.
Affected products
- IBM Netezza Software 11.3.0.3 through Interim Fix 002
Timeline
- 2026-09-03: disclosed