« Volver al listado

CVE-2024-39724

Estado: AplazadaMedia (5.3)—

IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not properly limit the allocation of system resources. An authenticated user with internal knowledge of the environment could exploit this weakness to cause a denial of service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-39724",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-39724",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-04T21:15:59.832540Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@us.ibm.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:big_sql:7.6:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:big_sql:7.7:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:big_sql:7.8:*:*:*:*:*:*:*"
          ],
          "vendor": "IBM",
          "product": "Db2 Big SQL on Cloud Pak for Data",
          "versions": [
            {
              "status": "affected",
              "version": "IBM Db2 Big SQL 7.6 on Cloud Pak for Data 4.8",
              "versionType": "semver",
              "lessThanOrEqual": "2.1.0"
            },
            {
              "status": "affected",
              "version": "IBM Db2 Big SQL 7.7 on Cloud Pak for Data 5.0"
            },
            {
              "status": "affected",
              "version": "IBM Db2 Big SQL 7.8 on Cloud Pak for Data 5.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-02-04T21:15:56.817",
  "references": [
    {
      "url": "https://www.ibm.com/support/pages/node/7257907",
      "source": "psirt@us.ibm.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@us.ibm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not properly limit the allocation of system resources. An authenticated user with internal knowledge of the environment could exploit this weakness to cause a denial of service."
    },
    {
      "lang": "es",
      "value": "IBM Db2 Big SQL en Cloud Pak for Data versiones 7.6 (en CP4D 4.8), 7.7 (en CP4D 5.0) y 7.8 (en CP4D 5.1) no limitan adecuadamente la asignación de recursos del sistema. Un usuario autenticado con conocimiento interno del entorno podría explotar esta debilidad para causar una denegación de servicio."
    }
  ],
  "lastModified": "2026-06-17T07:42:32.893",
  "sourceIdentifier": "psirt@us.ibm.com"
}