Impact
IBM Cloud Pak for Data System is vulnerable to a denial of service caused by an failure to properly limit resources, as identified by the CWE-770 Resource Exhaustion weakness. The flaw can cause the system to become unresponsive or crash, leading to loss of availability for users and applications that depend on the service.
Affected Systems
The affected product is IBM Cloud Pak for Data System. Versions 11.3.0.2 through Interim Fix 001 are impacted. The official fix for the vulnerability is available in IBM Cloud Pak for Data System 11.3.1.2-IF1-WS-ICPDS-NPS-Clients-fp326919.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity impact. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of public exploitation is uncertain, yet the DoS nature of the flaw remains a serious concern. Based on the description, it is inferred that an attacker could trigger the resource exhaustion by generating excessive load on the system, potentially from a remote endpoint if the service is exposed to external traffic.
OpenCVE Enrichment