## Summary
There is a vulnerability in GraphQL used by IBM Maximo Asset Management.
## Vulnerability Details
**CVEID: **[CVE-2022-37734]()
**DESCRIPTION: **GraphQL Java is vulnerable to a denial of service, caused by an uncontrolled resource consumption flaw. By sending a specially-crafted request using Directive overloading, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: [ https://exchange.xforce.ibmcloud.com/vulnerabilities/235781]() for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
## Affected Products and Versions
This vulnerability affects the following versions of the IBM Maximo Asset Management core product. Older versions of Maximo Asset Management may be impacted. The recommended action is to update to the latest version.
**Product versions affected:**
Affected Product(s) | Version(s)
—|—
IBM Maximo Asset Management | 7.6.1.3
Note: IBM Maximo Asset Management 7.6.1.2 is not affected.
* To determine the core product version, log in and view System Information. The core product version is the “Tivoli’s process automation engine” version. Please consult the [Platform Matrix]( “Platform Matrix” ) for a list of supported product combinations.
## Remediation/Fixes
The recommended solution is to download the appropriate Interim Fix or Fix Pack from Fix Central and apply for each affected product as soon as possible. Please see below for information on the fixes available for each product, version, and release. Follow the installation instructions in the âreadmeâ documentation provided with each fix pack or interim fix.
**For Maximo Asset Management 7.6:**
VRM | Fix Pack, Feature Pack, or Interim Fix | Download
—|—|—
7.6.1.3 |
Maximo Asset Management 7.6.1.3 iFix:
[7.6.1.3-TIV-MBS-IF007]( “7.6.1.3-TIV-MBS-IF007” ) or latest Interim Fix available
|
[FixCentral]( “FixCentral” )
## Workarounds and Mitigations
None