Allocation of Resources Without Limits or Throttling in GraphQL Java - CVE-2024-40094
Published: October 8, 2024 / Updated: August 22, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to GraphQL Java (aka graphql-java) does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM CICS TX Advanced
IBM CICS TX Standard
IBM TXSeries for Multiplatforms
Log Analysis
Cryostat
IBM SPSS Analytic Server
IBM Tivoli Netcool Impact
Red Hat build of Quarkus
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Backup-Archive Client
Storage Protect for Space Management
Maximo Application Suite - Predict Component
Maximo Application Suite - Monitor Component
Business Automation Insights
PowerVM NovaLink
Storage Protect Operations Center
Red Hat OpenShift Serverless
Planning Analytics Local
IBM Cloud Pak System
IBM WebSphere Application Server Liberty
How to mitigate CVE-2024-40094
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.27.0
IBM Tivoli Netcool Impact - update to 7.1.0.37
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.27.0
Storage Protect Backup-Archive Client - update to 8.1.27
Storage Protect for Space Management - update to 8.1.27.0
Maximo Application Suite - Predict Component - update to 9.0.4
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
Red Hat OpenShift Serverless - update to 1
Planning Analytics Local - addressed in versions 2.0.0.101, 2.0.9.21, 2.1.8
PowerVM NovaLink - addressed in versions 2.1.1-250103, 2.2.1.1-250103, 2.3.0-250103
IBM Cloud Pak System - addressed in versions 2.3.4.1 iFix 1, 2.3.5.0
Red Hat build of Quarkus - addressed in versions 3.2.12.SP1, 3.8.6.SP1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.8
IBM Maximo Asset Management - update to 7.6.1.3.25
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Storage Protect Operations Center - update to 8.1.26
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.18
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.18, 8.7.12, 9.0.3
IBM Maximo Application Suite - addressed in versions 8.10.24, 8.11.21, 9.0.10
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix35, 11.1.0.0 ifix27
IBM CICS TX Standard - update to 11.1.0.0 ifix28
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF004, 24.0.1-IF001
IBM WebSphere Application Server Liberty - update to 24.0.0.12
Links to Public Exploits and PoC-codes
External References
- https://github.com/graphql-java/graphql-java/releases/tag/v21.5
- https://github.com/graphql-java/graphql-java/releases/tag/v20.9
- https://github.com/graphql-java/graphql-java/releases/tag/v19.11
- https://github.com/graphql-java/graphql-java/commit/97743bc1b5caa2b0bd894dc8e128b47e4d771e4a
- https://github.com/graphql-java/graphql-java/discussions/3641
- https://github.com/graphql-java/graphql-java/pull/3539
Related Security Bulletins
- Allocation of resources without limits or throttling in GraphQL Java
- IBM Maximo Application Suite - Manage Component update for graphql-java-20.1.jar
- Multiple vulnerabilities in Red Hat build of Quarkus 3.8.6
- Multiple vulnerabilities in Red Hat build of Quarkus 3.2.12
- Multiple vulnerabilities in Red Hat build of Cryostat 3 on RHEL 8
- IBM Maximo Asset Management update for GraphQL Java
- IBM WebSphere Application Server Liberty update for GraphQL Java
- IBM PowerVM Novalink update for GraphQL Java
- IBM Operations Analytics - Log Analysis update for GraphQL Java
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- IBM CICS TX Standard update for GraphQL Java
- IBM CICS TX Advanced update for GraphQL Java
- IBM TXSeries for Multiplatforms update for GraphQL Java
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- IBM Watson Assistant for IBM Cloud Pak for Data update for GraphQL Java
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- IBM Maximo Application Suite - Predict Component update for GraphQL Java
- Multiple vulnerabilities in IBM Cloud Application Performance Management (APM)
- IBM Business Automation Workflow update for GraphQL Java
- IBM SPSS Analytic Server update for WebSphere Liberty
- Multiple vulnerabilities in IBM Planning Analytics
- IBM Maximo Application Suite - Monitor Component update for GraphQL Java
- IBM Cloud Pak System update for GraphQL Java
- IBM Maximo Application Suite update for GraphQL Java
- Multiple vulnerabilities in IBM Storage Protect Backup-Archive Client
- Multiple vulnerabilities in IBM Storage Protect for Space Management
- Multiple vulnerabilities in IBM Storage Protect for Virtual Environments (Data Protection for VMware and Data Protection for Hyper-V)
- IBM Storage Protect Operations Center update for GraphQL Java
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Tivoli Netcool Impact