Resource exhaustion in GraphQL Java - CVE-2022-37734

 

Resource exhaustion in GraphQL Java - CVE-2022-37734

Published: October 5, 2022


Vulnerability identifier: #VU67948
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-37734
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger send a specially crafted GraphQL query and consume available CPU resources, resulting in a denial of service.


Affected software

GraphQL Java
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Cloud Pak System
Vert.x
IBM FileNet Content Manager
Rational Asset Analyzer
PowerVM NovaLink
Robotic Process Automation for Cloud Pak
IBM Tivoli Netcool Impact
Red Hat Integration - Service Registry
IBM Cloud Pak for Multicloud Management Monitoring
IBM Maximo Asset Management
IBM TXSeries for Multiplatforms
IBM Cloud Application Performance Management (APM)
Maximo Manage Application in IBM Maximo Application Suite
IBM Maximo Application Suite
IBM Common Licensing
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM i
Event Streams
IBM WebSphere Application Server Liberty
IBM DS8000 Hardware Management Console

How to mitigate CVE-2022-37734

Install updates from vendor's website.

GraphQL Java - addressed in versions 17.4, 18.3
Vert.x - update to 4.3.3
IBM FileNet Content Manager - addressed in versions 5.5.8.0 IF003, 5.5.9.0 IF001
IBM Tivoli Netcool Impact - update to 7.1.0.28
Event Streams - update to 11.1.1
PowerVM NovaLink - addressed in versions 2.0.1-220923, 2.0.3.1.1-221121
Red Hat Integration - Service Registry - update to 2.3.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
IBM Maximo Asset Management - update to 7.6.1.3.7
IBM TXSeries for Multiplatforms - addressed in versions 8.1.0.3, 8.2.0.2, 9.1.0.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Maximo Manage Application in IBM Maximo Application Suite - update to 8.4.5
IBM Maximo Application Suite - update to 8.8.5
IBM Common Licensing - update to 9.0.0.1
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix13, 11.1.0.0 ifix6
IBM CICS TX Standard - update to 11.1.0.0 ifix6
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.15, 22.0.1.5
Robotic Process Automation for Cloud Pak - update to 21.0.7.1
IBM Robotic Process Automation - update to 21.0.7.1
IBM WebSphere Application Server Liberty - update to 22.0.0.12
IBM DS8000 Hardware Management Console - update to 89.33.34.0

External References

Related Security Bulletins