CVE-2022-23437
published 2022-01-24CVE-2022-23437: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML…
PriorityP336medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
4.44%
90.3th percentile
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | xerces-j | <= 2.12.1 | — |
| apache_software_foundation | apache_xerces | Apache XercesJ – 2.12.1 | — |
| debian | libxerces2-java | < libxerces2-java 2.12.2-1 (bookworm) | libxerces2-java 2.12.2-1 (bookworm) |
| nokogiri | nokogiri | >= 0 < 1.13.4 | 1.13.4 |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_plm | — | — |
| oracle | banking_deposits_and_lines_of_credit_servicing | — | — |
| oracle | banking_party_management | — | — |
| oracle | communications_asap | — | — |
| oracle | communications_element_manager | < 9.0 | 9.0 |
| oracle | communications_session_report_manager | < 9.0 | 9.0 |
| oracle | communications_session_route_manager | < 9.0 | 9.0 |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6.0.0 – 8.0.9.0 | — |
| oracle | financial_services_analytical_applications_infrastructure | >= 8.1.0.0 < 8.1.2.0 | 8.1.2.0 |
| oracle | financial_services_behavior_detection_platform | — | — |
| oracle | financial_services_behavior_detection_platform | — | — |
| oracle | financial_services_behavior_detection_platform | — | — |
| oracle | financial_services_behavior_detection_platform | 8.0.6.0.0 – 8.0.8.0 | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | financial_services_enterprise_case_management | — | — |
| oracle | financial_services_enterprise_case_management | — | — |
| oracle | financial_services_enterprise_case_management | — | — |
| oracle | financial_services_enterprise_case_management | — | — |
| oracle | financial_services_enterprise_case_management | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
ghsa6.5MEDIUM
osv7.5HIGH
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Web UI (Apache Xerces2 Java) — CVE-2022-23437
vendor_oracle·2024-10-15·CVSS 6.5
CVE-2022-23437 [MEDIUM] Oracle Oracle Communications Risk Matrix: Web UI (Apache Xerces2 Java) — CVE-2022-23437
Oracle Oracle Communications Risk Matrix: Web UI (Apache Xerces2 Java) vulnerability
CVE: CVE-2022-23437
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Commerce Risk Matrix: Endeca Application Controller (Apache Xerces2 Java) — CVE-2022-23437
vendor_oracle·2023-07-15·CVSS 6.5
CVE-2022-23437 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Endeca Application Controller (Apache Xerces2 Java) — CVE-2022-23437
Oracle Oracle Commerce Risk Matrix: Endeca Application Controller (Apache Xerces2 Java) vulnerability
CVE: CVE-2022-23437
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System, Workbench (Apache Xerces2 Java) — CVE-2022-23437
vendor_oracle·2023-04-15·CVSS 6.5
CVE-2022-23437 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Content Acquisition System, Workbench (Apache Xerces2 Java) — CVE-2022-23437
Oracle Oracle Commerce Risk Matrix: Content Acquisition System, Workbench (Apache Xerces2 Java) vulnerability
CVE: CVE-2022-23437
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Development Tools (Apache Xerces-J) — CVE-2022-23437
vendor_oracle·2023-01-15·CVSS 6.5
CVE-2022-23437 [MEDIUM] Oracle Oracle Insurance Applications Risk Matrix: Development Tools (Apache Xerces-J) — CVE-2022-23437
Oracle Oracle Insurance Applications Risk Matrix: Development Tools (Apache Xerces-J) vulnerability
CVE: CVE-2022-23437
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Commerce Risk Matrix: Endeca Integration (Apache Xerces-J) — CVE-2022-23437
vendor_oracle·2022-10-15·CVSS 6.5
CVE-2022-23437 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Endeca Integration (Apache Xerces-J) — CVE-2022-23437
Oracle Oracle Commerce Risk Matrix: Endeca Integration (Apache Xerces-J) vulnerability
CVE: CVE-2022-23437
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Global Lifecycle Management Risk Matrix: Patch Installer (Apache Xerces-J) — CVE-2022-23437
vendor_oracle·2022-07-15·CVSS 4.2
CVE-2022-23437 [MEDIUM] Oracle Oracle Global Lifecycle Management Risk Matrix: Patch Installer (Apache Xerces-J) — CVE-2022-23437
Oracle Oracle Global Lifecycle Management Risk Matrix: Patch Installer (Apache Xerces-J) vulnerability
CVE: CVE-2022-23437
CVSS: 4.2
Protocol: Local Logon
Remote exploit: No
Affected versions: Local
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Security (Apache Xerces-J) — CVE-2022-23437
vendor_oracle·2022-04-15·CVSS 6.5
CVE-2022-23437 [MEDIUM] Oracle Oracle Communications Risk Matrix: Security (Apache Xerces-J) — CVE-2022-23437
Oracle Oracle Communications Risk Matrix: Security (Apache Xerces-J) vulnerability
CVE: CVE-2022-23437
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
xerces-j2: infinite loop when handling specially crafted XML document payloads
vendor_redhat·2022-01-24·CVSS 6.5
CVE-2022-23437 [MEDIUM] CWE-835 xerces-j2: infinite loop when handling specially crafted XML document payloads
xerces-j2: infinite loop when handling specially crafted XML document payloads
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
A flaw was found in the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This issue causes the XercesJ XML parser to wait in an infinite loop, which may consume system resources for a prolonged duration, leading to a denial of service condition.
Package: xerces-j2 (Red Hat Enterprise Linux 6) - Out of support scope
Pac
Debian
CVE-2022-23437: libxerces2-java - There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when ...
vendor_debian·2022·CVSS 6.5
CVE-2022-23437 [MEDIUM] CVE-2022-23437: libxerces2-java - There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when ...
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
Scope: local
bookworm: resolved (fixed in 2.12.2-1)
bullseye: open
forky: resolved (fixed in 2.12.2-1)
sid: resolved (fixed in 2.12.2-1)
trixie: resolved (fixed in 2.12.2-1)
OSV
pillow vulnerability
osv·2022-10-24·CVSS 7.5
CVE-2022-22817 pillow vulnerability
pillow vulnerability
USN-5227-1 fixed vulnerabilities in Pillow. It was discovered that the fix
for CVE-2022-22817 was incomplete. This update fixes the problem.
Original advisory details:
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and
Ubuntu 21.04. (CVE-2021-34552)
It was discovered that Pill
GHSA
XML Injection in Xerces Java affects Nokogiri
ghsa·2022-04-11·CVSS 6.5
CVE-2022-23437 [MEDIUM] CWE-91 XML Injection in Xerces Java affects Nokogiri
XML Injection in Xerces Java affects Nokogiri
## Summary
Nokogiri v1.13.4 updates the vendored `xerces:xercesImpl` from 2.12.0 to 2.12.2, which addresses [CVE-2022-23437](https://nvd.nist.gov/vuln/detail/CVE-2022-23437). That CVE is scored as CVSS 6.5 "Medium" on the NVD record.
Please note that this advisory only applies to the **JRuby** implementation of Nokogiri `= v1.13.4`.
## Impact
### [CVE-2022-23437](https://nvd.nist.gov/vuln/detail/CVE-2022-23437) in xerces-J
- **Severity**: Medium
- **Type**: [CWE-91](https://cwe.mitre.org/data/definitions/91.html) XML Injection (aka Blind XPath Injection)
- **Description**: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to
OSV
XML Injection in Xerces Java affects Nokogiri
osv·2022-04-11·CVSS 6.5
CVE-2022-23437 [MEDIUM] XML Injection in Xerces Java affects Nokogiri
XML Injection in Xerces Java affects Nokogiri
## Summary
Nokogiri v1.13.4 updates the vendored `xerces:xercesImpl` from 2.12.0 to 2.12.2, which addresses [CVE-2022-23437](https://nvd.nist.gov/vuln/detail/CVE-2022-23437). That CVE is scored as CVSS 6.5 "Medium" on the NVD record.
Please note that this advisory only applies to the **JRuby** implementation of Nokogiri `= v1.13.4`.
## Impact
### [CVE-2022-23437](https://nvd.nist.gov/vuln/detail/CVE-2022-23437) in xerces-J
- **Severity**: Medium
- **Type**: [CWE-91](https://cwe.mitre.org/data/definitions/91.html) XML Injection (aka Blind XPath Injection)
- **Description**: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to
OSV
Infinite Loop in Apache Xerces Java
osv·2022-01-27
CVE-2022-23437 [MEDIUM] Infinite Loop in Apache Xerces Java
Infinite Loop in Apache Xerces Java
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
GHSA
Infinite Loop in Apache Xerces Java
ghsa·2022-01-27
CVE-2022-23437 [MEDIUM] CWE-91 Infinite Loop in Apache Xerces Java
Infinite Loop in Apache Xerces Java
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
OSV
CVE-2022-23437: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads
osv·2022-01-24·CVSS 6.5
CVE-2022-23437 [MEDIUM] CVE-2022-23437: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2022/01/24/3https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dlhttps://security.netapp.com/advisory/ntap-20221028-0005/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttp://www.openwall.com/lists/oss-security/2022/01/24/3https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dlhttps://security.netapp.com/advisory/ntap-20221028-0005/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2022-01-24
Published