Junglewise Threat Intelligence

CVE-2026-9744: IBM Netezza Software TLS certificate validation bypass

CVE-2026-9744 · Severity: medium · CVSS 5.3 · Published 2026-09-03

Technologies: IBM Netezza Performance Server, IBM Netezza Software. Vendors: IBM.

Executive brief

IBM Netezza Software, a data warehouse and analytics platform, fails to properly validate TLS certificates, making it vulnerable to man-in-the-middle attacks. An attacker positioned on the network could intercept encrypted connections and obtain sensitive data such as authentication credentials or query results without detection.

Technical details

IBM Netezza Software versions 11.3.0.3 through Interim Fix 002 do not properly validate TLS/SSL certificates during secure communications. The vulnerability allows an attacker with network-level access to perform man-in-the-middle (MITM) attacks by presenting an invalid or spoofed certificate that the application will accept. No authentication or user interaction is required; the flaw is exposed to any attacker with network access between the client and Netezza server. An attacker can intercept encrypted traffic and harvest sensitive information including credentials, configuration data, and query results. The vulnerability has been addressed in IBM Netezza Software version 11.3.1.3 or later.

Affected products

  • IBM Netezza Software 11.3.0.3 through Interim Fix 002

Timeline

  • 2026-09-03: disclosed

References

Related threats