Junglewise Threat Intelligence

CVE-2024-54178: IBM Db2 on Cloud Pak for Data denial of service in database creation

CVE-2024-54178 · Severity: medium · CVSS 6.5 · Published 2026-06-22

Technologies: IBM Db2 on Cloud Pak for Data, IBM Db2 Warehouse on Cloud Pak for Data. Vendors: IBM.

Executive brief

IBM Db2 and Db2 Warehouse on Cloud Pak for Data are vulnerable to a flaw that allows an authorized user to crash the service or make it unavailable. By attempting to create new databases, a user can trigger a resource exhaustion issue that prevents the system from functioning correctly. This could lead to operational downtime and the inability for other users to access or manage data.

Technical details

A denial of service vulnerability exists in IBM Db2 and Db2 Warehouse on Cloud Pak for Data due to improper allocation of resources (CWE-770). An authenticated attacker with sufficient privileges to create new databases can trigger this flaw to exhaust system resources, leading to a service crash or unavailability. The vulnerability is reachable over the network and requires low-level authentication but no user interaction. Affected versions include 4.8.x and 5.0.x through 5.3.x. IBM has released security updates to address this and other vulnerabilities in the Cloud Pak for Data environment.

Affected products

  • IBM Db2 on Cloud Pak for Data 4.8, 5.0, 5.1, 5.2, 5.3
  • IBM Db2 Warehouse on Cloud Pak for Data 4.8, 5.0, 5.1, 5.2, 5.3

Timeline

  • 2026-06-22: disclosed
  • 2026-06-22: advisory

References

Related threats