Description
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper limitation of resources.
Published: 2026-08-28
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Cloud Pak for Data System is vulnerable to a denial of service caused by an failure to properly limit resources, as identified by the CWE-770 Resource Exhaustion weakness. The flaw can cause the system to become unresponsive or crash, leading to loss of availability for users and applications that depend on the service.

Affected Systems

The affected product is IBM Cloud Pak for Data System. Versions 11.3.0.2 through Interim Fix 001 are impacted. The official fix for the vulnerability is available in IBM Cloud Pak for Data System 11.3.1.2-IF1-WS-ICPDS-NPS-Clients-fp326919.

Risk and Exploitability

The CVSS score of 6.2 indicates a moderate severity impact. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of public exploitation is uncertain, yet the DoS nature of the flaw remains a serious concern. Based on the description, it is inferred that an attacker could trigger the resource exhaustion by generating excessive load on the system, potentially from a remote endpoint if the service is exposed to external traffic.

Generated by OpenCVE AI on August 28, 2026 at 23:21 UTC.

Remediation

Vendor Solution

Fix Version Remediation/Fixes IBM Cloud Pak for Data System 11.3.1.2-IF1-WS-ICPDS-NPS-Clients-fp326919 https://www.ibm.com/support/fixcentral/quickorder


OpenCVE Recommended Actions

  • Upgrade IBM Cloud Pak for Data System to version 11.3.1.2-IF1-WS-ICPDS-NPS-Clients-fp326919 to apply the vendor fix.
  • After upgrading, verify that resource limits and quotas are properly configured to prevent future exhaustion of system resources.
  • Continuously monitor CPU and memory metrics for abnormal spikes and apply additional patch updates as they become available.

Generated by OpenCVE AI on August 28, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper limitation of resources.
Title Vulnerabilities exists in IBM Cloud Pak for Data System
First Time appeared Ibm
Ibm cloud Pak For Data System
Weaknesses CWE-770
CPEs cpe:2.3:a:ibm:cloud_pak_for_data_system:11.3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_data_system:interim:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Data System
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Cloud Pak For Data System
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:54:02.208Z

Reserved: 2026-03-06T22:12:51.971Z

Link: CVE-2026-3686

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:49.180

Modified: 2026-08-28T22:16:49.180

Link: CVE-2026-3686

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:30:17Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling