Описание
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.
Ссылки
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.3.1.3 (исключая)
cpe:2.3:a:ibm:netezza_performance_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 9%
0.00194
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-283
Связанные уязвимости
CVSS3: 6.5
github
14 дней назад
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.
EPSS
Процентиль: 9%
0.00194
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-283