IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not properly limit the allocation of system resources. An authenticated user with internal knowledge of the environment could exploit this weakness to cause a denial of service.
History

Wed, 04 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Feb 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Big SQL 7.6 on Cloud Pak for Data 4.8, 7.7 on Cloud Pak for Data 5.0, and 7.8 on Cloud Pak for Data 5.1 does not properly limit allocation of resources which could allow an authenticated user with internal knowledge of the system to cause a denial of service. IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not properly limit the allocation of system resources. An authenticated user with internal knowledge of the environment could exploit this weakness to cause a denial of service.
First Time appeared Ibm
Ibm big Sql
CPEs cpe:2.3:a:ibm:big_sql:7.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:big_sql:7.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:big_sql:7.8:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm big Sql

Wed, 04 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Db2 Big SQL 7.6 on Cloud Pak for Data 4.8, 7.7 on Cloud Pak for Data 5.0, and 7.8 on Cloud Pak for Data 5.1 does not properly limit allocation of resources which could allow an authenticated user with internal knowledge of the system to cause a denial of service.
Title IBM Db2 Big SQL on Cloud Pak for Data is vulnerable to a denial of service due to lack of throttling on an API
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-02-04T20:52:21.777Z

Updated: 2026-02-04T21:30:20.090Z

Reserved: 2024-06-28T09:34:20.322Z

Link: CVE-2024-39724

cve-icon Vulnrichment

Updated: 2026-02-04T21:16:04.842Z

cve-icon NVD

Status : Received

Published: 2026-02-04T21:15:56.817

Modified: 2026-02-04T22:15:56.363

Link: CVE-2024-39724

cve-icon Redhat

No data.