Allocation of Resources Without Limits or Throttling in GraphQL Java - CVE-2023-28867
Published: June 1, 2023
Vulnerability identifier: #VU76753
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28867
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can send a crafted GraphQL query that causes stack consumption.
Affected software
GraphQL Java
IBM CICS TX Advanced
IBM CICS TX Standard
webMethods API Gateway
PowerVM NovaLink
IBM Planning Analytics Workspace
IBM Security Directory Suite
Storage Protect Operations Center
Planning Analytics Local
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat Integration - Service Registry
IBM Match 360
IBM Spectrum Control
IBM Tivoli Netcool Impact
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
Maximo Manage Application in IBM Maximo Application Suite
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Security Verify Access
IBM WebSphere Application Server Liberty
IBM CICS TX Advanced
IBM CICS TX Standard
webMethods API Gateway
PowerVM NovaLink
IBM Planning Analytics Workspace
IBM Security Directory Suite
Storage Protect Operations Center
Planning Analytics Local
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat Integration - Service Registry
IBM Match 360
IBM Spectrum Control
IBM Tivoli Netcool Impact
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
Maximo Manage Application in IBM Maximo Application Suite
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Security Verify Access
IBM WebSphere Application Server Liberty
How to mitigate CVE-2023-28867
Install updates from vendor's website.
GraphQL Java - update to 20.1
webMethods API Gateway - update to 10.15 Fix 10
PowerVM NovaLink - addressed in versions 2.0.3.1.1-230726, 2.1.1-230725
Planning Analytics Local - update to 2.0.9.19
IBM Planning Analytics Workspace - update to 2.0.91
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
Red Hat Integration - Service Registry - update to 2.4.3
IBM Match 360 - update to 4.7.4
IBM Spectrum Control - update to 5.4.10.2
IBM Tivoli Netcool Impact - update to 7.1.0.31
IBM Maximo Asset Management - update to 7.6.1.3.8
IBM Security Directory Suite - update to 8.0.1.21
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Protect Operations Center - update to 8.1.20
IBM TXSeries for Multiplatforms - addressed in versions 8.2.0.2, 9.1.0.2
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.4.9, 8.5.5, 8.6.1
IBM Maximo Application Suite - addressed in versions 8.9.8, 8.10.3
IBM Security Verify Access - update to 10.0.7.0
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix20, 11.1.0.0 ifix12
IBM CICS TX Standard - update to 11.1.0.0 ifix12
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.33, 23.0.2.5
IBM WebSphere Application Server Liberty - update to 23.0.0.6
webMethods API Gateway - update to 10.15 Fix 10
PowerVM NovaLink - addressed in versions 2.0.3.1.1-230726, 2.1.1-230725
Planning Analytics Local - update to 2.0.9.19
IBM Planning Analytics Workspace - update to 2.0.91
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
Red Hat Integration - Service Registry - update to 2.4.3
IBM Match 360 - update to 4.7.4
IBM Spectrum Control - update to 5.4.10.2
IBM Tivoli Netcool Impact - update to 7.1.0.31
IBM Maximo Asset Management - update to 7.6.1.3.8
IBM Security Directory Suite - update to 8.0.1.21
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Protect Operations Center - update to 8.1.20
IBM TXSeries for Multiplatforms - addressed in versions 8.2.0.2, 9.1.0.2
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.4.9, 8.5.5, 8.6.1
IBM Maximo Application Suite - addressed in versions 8.9.8, 8.10.3
IBM Security Verify Access - update to 10.0.7.0
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix20, 11.1.0.0 ifix12
IBM CICS TX Standard - update to 11.1.0.0 ifix12
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.33, 23.0.2.5
IBM WebSphere Application Server Liberty - update to 23.0.0.6
External References
- https://github.com/graphql-java/graphql-java/pull/3112
- https://github.com/graphql-java/graphql-java/releases/tag/v19.4
- https://github.com/graphql-java/graphql-java/releases/tag/v17.5
- https://github.com/graphql-java/graphql-java/releases/tag/v18.4
- https://github.com/graphql-java/graphql-java/releases/tag/v20.1
Related Security Bulletins
- Allocation of resources without limits or throttling in IBM WebSphere Application Server Liberty
- Multiple vulnerabilities in Red Hat Integration - Service Registry
- Allocation of resources without limits or throttling in IBM Maximo Asset Management
- Allocation of resources without limits or throttling in IBM Maximo Manage application in IBM Maximo Application Suite
- Allocation of resources without limits or throttling in IBM CICS TX Advanced
- Allocation of resources without limits or throttling in IBM TXSeries for Multiplatforms
- Allocation of resources without limits or throttling in IBM CICS TX Standard
- Allocation of resources without limits or throttling in IBM PowerVM Novalink
- Allocation of resources without limits or throttling in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in IBM Application Performance Management
- Allocation of resources without limits or throttling in IBM Storage Protect Operations Center
- Allocation of resources without limits or throttling in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in IBM Spectrum Control
- Multiple vulnerabilities in IBM Planning Analytics
- Multiple vulnerabilities in webMethods API Gateway
- Allocation of resources without limits or throttling in IBM Match 360
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Security Directory Suite