CVE-2024-39724
Unknown
Unknown - Not Provided
Resource Exhaustion Vulnerability in IBM Db2 Big SQL Causing DoS
Publication date: 2026-02-04
Last updated on: 2026-02-04
Assigner: IBM Corporation
Description
Description
IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not properly limit the allocation of system resources. An authenticated user with internal knowledge of the environment could exploit this weakness to cause a denial of service.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | db2_big_sql | 7.6 |
| ibm | db2_big_sql | 7.7 |
| ibm | db2_big_sql | to 5.1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-770 | The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated. |