5.3
CVE-2024-39724
- EPSS 0.02%
- Veröffentlicht 04.02.2026 20:52:21
- Zuletzt bearbeitet 05.02.2026 14:57:20
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not properly limit the allocation of system resources. An authenticated user with internal knowledge of the environment could exploit this weakness to cause a denial of service.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerIBM
≫
Produkt
Db2 Big SQL on Cloud Pak for Data
Version <=
2.1.0
Version
IBM Db2 Big SQL 7.6 on Cloud Pak for Data 4.8
Status
affected
Version
IBM Db2 Big SQL 7.7 on Cloud Pak for Data 5.0
Status
affected
Version
IBM Db2 Big SQL 7.8 on Cloud Pak for Data 5.1
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.036 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.