cbcvebase.
CVE-2022-23437
published 2022-01-24

CVE-2022-23437: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML…

PriorityP336medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
4.44%
90.4th percentile
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
apachexerces-j<= 2.12.1
apache_software_foundationapache_xercesApache XercesJ – 2.12.1
debianlibxerces2-java< libxerces2-java 2.12.2-1 (bookworm)libxerces2-java 2.12.2-1 (bookworm)
nokogirinokogiri>= 0 < 1.13.41.13.4
oracleagile_engineering_data_management
oracleagile_plm
oraclebanking_deposits_and_lines_of_credit_servicing
oraclebanking_party_management
oraclecommunications_asap
oraclecommunications_element_manager< 9.09.0
oraclecommunications_session_report_manager< 9.09.0
oraclecommunications_session_route_manager< 9.09.0
oraclefinancial_services_analytical_applications_infrastructure8.0.6.0.0 – 8.0.9.0
oraclefinancial_services_analytical_applications_infrastructure>= 8.1.0.0 < 8.1.2.08.1.2.0
oraclefinancial_services_behavior_detection_platform
oraclefinancial_services_behavior_detection_platform
oraclefinancial_services_behavior_detection_platform
oraclefinancial_services_behavior_detection_platform8.0.6.0.0 – 8.0.8.0
oraclefinancial_services_crime_and_compliance_management_studio
oraclefinancial_services_crime_and_compliance_management_studio
oraclefinancial_services_enterprise_case_management
oraclefinancial_services_enterprise_case_management
oraclefinancial_services_enterprise_case_management
oraclefinancial_services_enterprise_case_management
oraclefinancial_services_enterprise_case_management

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
ghsa6.5MEDIUM
osv7.5HIGH
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.