CVE-2024-54178: Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denial of service when creating new databases due to improper allocation of resources.
Other sources
IBM Db2U could allow an authenticated user to cause a denial of service when creating new databases due to improper allocation of resources.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 - Upgrade
Upgrade
IBM Db2Uto a version that resolves this vulnerability.Fixed in 5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54178?
The severity of CVE-2024-54178 is rated as medium with a score of 6.5.
How do I fix CVE-2024-54178?
To mitigate CVE-2024-54178, ensure you update to the latest versions of IBM Db2 on Cloud Pak for Data and Db2 Warehouse.
What types of systems are affected by CVE-2024-54178?
CVE-2024-54178 affects IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8 through 5.3.
What is the main impact of CVE-2024-54178?
CVE-2024-54178 can lead to a denial of service due to improper allocation of resources during database creation.
Who can exploit CVE-2024-54178?
CVE-2024-54178 can be exploited by authenticated users of the affected IBM Db2 systems.