Executive brief
IBM Netezza Software fails to validate S3 bucket ownership when performing cloud storage operations, allowing an attacker to exploit naming collisions or misconfigurations to redirect requests to an attacker-controlled bucket. This could result in sensitive data being written to or read from the wrong cloud storage location, compromising data confidentiality and integrity.
Technical details
The vulnerability exists in IBM Netezza Software versions 11.3.0.3 through Interim Fix 002, where S3 API operations omit validation of the ExpectedBucketOwner parameter. This allows an attacker to exploit bucket naming collisions or application misconfigurations to redirect requests to an unintended S3 bucket under their control. An attacker with network access can craft requests that take advantage of this missing validation. The flaw is fixed in version 11.3.1.3.
Affected products
- IBM Netezza Software 11.3.0.3 through Interim Fix 002
Timeline
- 2026-09-03: disclosed