Junglewise Threat Intelligence

CVE-2026-9036: IBM Netezza Software improper TLS certificate validation

CVE-2026-9036 · Severity: medium · CVSS 5.9 · Published 2026-09-03

Technologies: IBM Netezza Performance Server, IBM Netezza Software. Vendors: IBM.

Executive brief

IBM Netezza Software, a data warehouse and analytics platform, does not properly validate TLS certificates. An attacker positioned on the network could intercept encrypted communications between the software and servers it connects to, potentially stealing sensitive data without being detected. This allows unauthorized surveillance of database queries, credentials, and other confidential information in transit.

Technical details

The vulnerability is an improper certificate validation flaw (CWE-295) in IBM Netezza Software versions 11.3.0.3 through Interim Fix 002. The software does not properly validate or verify TLS certificates when establishing secure connections, allowing an attacker to perform man-in-the-middle (MITM) attacks over a network. An attacker does not require authentication and can intercept traffic if positioned on the network path. The attacker can read sensitive data transmitted over these connections. The vulnerability is fixed in version 11.3.1.3 or later.

Affected products

  • IBM Netezza Software 11.3.0.3 through Interim Fix 002

Timeline

  • 2026-09-03: disclosed

References

Related threats