IBM Db2 Big SQL Resource Allocation Vulnerability Leading to Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in IBM Db2 Big SQL on Cloud Pak for Data, affecting versions 7.6 on CP4D 4.8, 7.7 on CP4D 5.0, and 7.8 on CP4D 5.1. The vulnerability arises from improper limitations on resource allocation, allowing an authenticated user with internal knowledge of the environment to disrupt service.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, causing interruptions in service availability.

Remediation

Users are advised to upgrade IBM Db2 Big SQL to version 8.2 or later, available on IBM Cloud Pak for Data 5.2 or later. Instructions for upgrading Cloud Pak for Data and the Db2 Big SQL service can be found in the IBM Cloud Pak for Data documentation.

Added: Feb 4, 2026, 9:34 PM
Updated: Feb 4, 2026, 10:40 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
4.5
remediation
7.7
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.