Allocation of Resources Without Limits or Throttling in GraphQL Java - CVE-2023-28867

 

Allocation of Resources Without Limits or Throttling in GraphQL Java - CVE-2023-28867

Published: June 1, 2023


Vulnerability identifier: #VU76753
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28867
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can send a crafted GraphQL query that causes stack consumption.


Affected software

GraphQL Java
IBM CICS TX Advanced
IBM CICS TX Standard
webMethods API Gateway
PowerVM NovaLink
IBM Planning Analytics Workspace
IBM Security Directory Suite
Storage Protect Operations Center
Planning Analytics Local
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat Integration - Service Registry
IBM Match 360
IBM Spectrum Control
IBM Tivoli Netcool Impact
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
Maximo Manage Application in IBM Maximo Application Suite
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Security Verify Access
IBM WebSphere Application Server Liberty

How to mitigate CVE-2023-28867

Install updates from vendor's website.

GraphQL Java - update to 20.1
webMethods API Gateway - update to 10.15 Fix 10
PowerVM NovaLink - addressed in versions 2.0.3.1.1-230726, 2.1.1-230725
Planning Analytics Local - update to 2.0.9.19
IBM Planning Analytics Workspace - update to 2.0.91
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
Red Hat Integration - Service Registry - update to 2.4.3
IBM Match 360 - update to 4.7.4
IBM Spectrum Control - update to 5.4.10.2
IBM Tivoli Netcool Impact - update to 7.1.0.31
IBM Maximo Asset Management - update to 7.6.1.3.8
IBM Security Directory Suite - update to 8.0.1.21
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Protect Operations Center - update to 8.1.20
IBM TXSeries for Multiplatforms - addressed in versions 8.2.0.2, 9.1.0.2
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.4.9, 8.5.5, 8.6.1
IBM Maximo Application Suite - addressed in versions 8.9.8, 8.10.3
IBM Security Verify Access - update to 10.0.7.0
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix20, 11.1.0.0 ifix12
IBM CICS TX Standard - update to 11.1.0.0 ifix12
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.33, 23.0.2.5
IBM WebSphere Application Server Liberty - update to 23.0.0.6

External References

Related Security Bulletins