CVE-2026-9745CWE-283

CVE-2026-9745

Medium · published September 4, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
9.1
In the wild
Unconfirmed
What it is

IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00194 · 9.1th percentile
Weakness
CWE-283 · Unverified Ownership
Published
2026-09-04T01:17Z
References (1)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 03 SEP 20:41Z
    Vulnerabilities exists in IBM Netezza Software
    cvelistv5