Security Bulletin: IBM WebSphere Application Server Liberty is vulnerable to denial of service due to GraphQL Java (CVE-2022-37734)

## Summary There is a vulnerability in the GraphQL Java library used by IBM WebSphere Application Server Liberty with the mpGraphQL-1.0 or mpGraphQL-2.0 feature enabled. This has been addressed. ## Vu ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Using Spring for GraphQL with Spring Data Neo4j

## Introduction _This is a guest blog post by [Gerrit Meier]() from [Neo4j]() who maintain(s) the Spring Data Neo4j module._ A few weeks ago version 1.2.0 of Spring (for) GraphQL was released with a b ...

Continue Reading
GraphQL vs gRPC: Which One Creates More Secure APIs?

Learn about the security capabilities of GraphQL and gRPC, how they perform authentication/authorization, and how they compare to REST. In addition, discover common attack vectors for both API framewo ...

Continue Reading
Security Bulletin: IBM WebSphere Application Server Liberty, which is bundled with IBM WebSphere Hybrid Edition, is vulnerable to a denial of service due to GraphQL Java (CVE-2023-28867)

## Summary IBM WebSphere Application Server Liberty, which is bundled with IBM WebSphere Hybrid Edition, is vulnerable to a denial of service due to GraphQL Java (CVE-2023-28867) ## Vulnerability Deta ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Security Bulletin: IBM WebSphere Application Server Liberty, which is bundled with IBM Cloud Pak for Applications, is vulnerable to a denial of service due to GraphQL Java (CVE-2023-28867)

## Summary IBM WebSphere Application Server Liberty, which is bundled with IBM Cloud Pak for Applications, is vulnerable to a denial of service due to GraphQL Java (CVE-2023-28867) ## Vulnerability De ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-2478

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2023-0921

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue descri ...

Continue Reading
Security Bulletin: There is a vulnerability in GraphQL used by IBM Maximo Asset Management (CVE-2022-37734)

## Summary There is a vulnerability in GraphQL used by IBM Maximo Asset Management. ## Vulnerability Details **CVEID: **[CVE-2022-37734]() **DESCRIPTION: **GraphQL Java is vulnerable to a denial of se ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: