{"api_version":"1","generated_at":"2026-09-05T03:54:33+00:00","cve":"CVE-2026-9736","urls":{"html":"https://cve.report/CVE-2026-9736","api":"https://cve.report/api/cve/CVE-2026-9736.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-9736","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-9736"},"summary":{"title":"Vulnerabilities exists in IBM Netezza Software","description":"IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-09-03 21:17:24","updated_at":"2026-09-05 03:17:24"},"problem_types":["CWE-117","CWE-117 CWE-117 Improper Output Neutralization for Logs"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7284359","name":"https://www.ibm.com/support/pages/node/7284359","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-9736","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9736","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Netezza Software","version":"affected 11.3.0.3 Interim Fix 002 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerability now.\n\n\n\n\n\nFixed Version\n\n\n\nRemediation/Fixes: 11.3.1.3\n\n\n\nIBM Netezza Software\n\n\n\nAvailable from  https://w3.ibm.com/w3publisher/software-downloads","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"9736","cve":"CVE-2026-9736","epss":"0.001860000","percentile":"0.081970000","score_date":"2026-09-04","updated_at":"2026-09-05 00:04:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-9736","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-05T02:17:24.368152Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-05T02:18:22.313Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:netezza_software:11.3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:netezza_software:interim:interim_fix_002:*:*:*:*:*:*"],"product":"Netezza Software","vendor":"IBM","versions":[{"lessThanOrEqual":"Interim Fix 002","status":"affected","version":"11.3.0.3","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.</p>"}],"value":"IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-117","description":"CWE-117 Improper Output Neutralization for Logs","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-03T20:42:38.769Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7284359"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<div><p>IBM strongly recommends addressing the vulnerability now.</p></div><div><table><colgroup><col/><col/></colgroup><tbody><tr><td><p>Fixed Version</p></td><td><p>Remediation/Fixes: 11.3.1.3</p></td></tr><tr><td><p>IBM Netezza Software</p></td><td><p>Available from <a href=\"https://w3.ibm.com/w3publisher/software-downloads\" rel=\"nofollow\">https://w3.ibm.com/w3publisher/software-downloads</a></p></td></tr></tbody></table></div><p></p>"}],"value":"IBM strongly recommends addressing the vulnerability now.\n\n\n\n\n\nFixed Version\n\n\n\nRemediation/Fixes: 11.3.1.3\n\n\n\nIBM Netezza Software\n\n\n\nAvailable from  https://w3.ibm.com/w3publisher/software-downloads"}],"title":"Vulnerabilities exists in IBM Netezza Software"}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-9736","datePublished":"2026-09-03T20:42:38.769Z","dateReserved":"2026-05-27T17:27:08.972Z","dateUpdated":"2026-09-05T02:18:22.313Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-03 21:17:24","lastModifiedDate":"2026-09-05 03:17:24","problem_types":["CWE-117","CWE-117 CWE-117 Improper Output Neutralization for Logs"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-05T02:17:24.368152Z","id":"CVE-2026-9736","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"9736","Ordinal":"1","Title":"Vulnerabilities exists in IBM Netezza Software","CVE":"CVE-2026-9736","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"9736","Ordinal":"1","NoteData":"IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.","Type":"Description","Title":"Vulnerabilities exists in IBM Netezza Software"}]}}}