{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-9036",
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "state": "PUBLISHED",
        "assignerShortName": "ibm",
        "dateReserved": "2026-05-19T16:54:27.268Z",
        "datePublished": "2026-09-03T20:42:08.092Z",
        "dateUpdated": "2026-09-03T20:42:08.092Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
                "shortName": "ibm",
                "dateUpdated": "2026-09-03T20:42:08.092Z"
            },
            "title": "Vulnerabilities exists in IBM Netezza Software",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-295",
                            "description": "CWE-295 Improper Certificate Validation",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "IBM",
                    "product": "Netezza Software",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "11.3.0.3",
                            "lessThanOrEqual": "Interim Fix 002",
                            "versionType": "semver"
                        }
                    ],
                    "cpes": [
                        "cpe:2.3:a:ibm:netezza_software:11.3.0.3:*:*:*:*:*:*:*",
                        "cpe:2.3:a:ibm:netezza_software:interim:interim_fix_002:*:*:*:*:*:*"
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.ibm.com/support/pages/node/7284359",
                    "tags": [
                        "vendor-advisory",
                        "patch"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "HIGH",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "NONE",
                        "availabilityImpact": "NONE",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 5.9,
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "IBM strongly recommends addressing the vulnerability now.\n\n\n\n\n\nFixed Version\n\n\n\nRemediation/Fixes: 11.3.1.3\n\n\n\nIBM Netezza Software\n\n\n\nAvailable from  https://w3.ibm.com/w3publisher/software-downloads",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<div><p>IBM strongly recommends addressing the vulnerability now.</p></div><div><table><colgroup><col/><col/></colgroup><tbody><tr><td><p>Fixed Version</p></td><td><p>Remediation/Fixes: 11.3.1.3</p></td></tr><tr><td><p>IBM Netezza Software</p></td><td><p>Available from <a href=\"https://w3.ibm.com/w3publisher/software-downloads\" rel=\"nofollow\">https://w3.ibm.com/w3publisher/software-downloads</a></p></td></tr></tbody></table></div><p></p>"
                        }
                    ]
                }
            ]
        }
    }
}