Allocation of Resources Without Limits or Throttling in GraphQL Java - CVE-2024-40094

 

Allocation of Resources Without Limits or Throttling in GraphQL Java - CVE-2024-40094

Published: October 8, 2024 / Updated: August 22, 2025


Vulnerability identifier: #VU98137
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-40094
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to GraphQL Java (aka graphql-java) does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

GraphQL Java
IBM CICS TX Advanced
IBM CICS TX Standard
IBM TXSeries for Multiplatforms
Log Analysis
Cryostat
IBM SPSS Analytic Server
IBM Tivoli Netcool Impact
Red Hat build of Quarkus
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Backup-Archive Client
Storage Protect for Space Management
Maximo Application Suite - Predict Component
Maximo Application Suite - Monitor Component
Business Automation Insights
PowerVM NovaLink
Storage Protect Operations Center
Red Hat OpenShift Serverless
Planning Analytics Local
IBM Cloud Pak System
IBM WebSphere Application Server Liberty

How to mitigate CVE-2024-40094

Install updates from vendor's website.

GraphQL Java - update to 21.5
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.27.0
IBM Tivoli Netcool Impact - update to 7.1.0.37
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.27.0
Storage Protect Backup-Archive Client - update to 8.1.27
Storage Protect for Space Management - update to 8.1.27.0
Maximo Application Suite - Predict Component - update to 9.0.4
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
Red Hat OpenShift Serverless - update to 1
Planning Analytics Local - addressed in versions 2.0.0.101, 2.0.9.21, 2.1.8
PowerVM NovaLink - addressed in versions 2.1.1-250103, 2.2.1.1-250103, 2.3.0-250103
IBM Cloud Pak System - addressed in versions 2.3.4.1 iFix 1, 2.3.5.0
Red Hat build of Quarkus - addressed in versions 3.2.12.SP1, 3.8.6.SP1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.8
IBM Maximo Asset Management - update to 7.6.1.3.25
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Storage Protect Operations Center - update to 8.1.26
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.18
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.18, 8.7.12, 9.0.3
IBM Maximo Application Suite - addressed in versions 8.10.24, 8.11.21, 9.0.10
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix35, 11.1.0.0 ifix27
IBM CICS TX Standard - update to 11.1.0.0 ifix28
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF004, 24.0.1-IF001
IBM WebSphere Application Server Liberty - update to 24.0.0.12

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins