PT-2026-30219 · Amazon · Amazon Athena Odbc Driver+1
CVE-2026-35560
·
Published
2026-04-03
·
Updated
2026-04-03
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Amazon Athena ODBC driver versions prior to 2.1.0.0
Description
Improper certificate validation in the identity provider connection components may allow a man-in-the-middle threat actor to intercept authentication credentials. This occurs due to insufficient default transport security when connecting to external identity providers. This issue does not affect connections made directly to Athena.
Recommendations
Update to version 2.1.0.0.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Athena Odbc Driver
Athena Odbc