CVE-2022-34169
published 2022-07-19CVE-2022-34169: The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java…
PriorityP265high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
81.04%
99.6th percentile
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | xalan-java | <= 2.7.2 | — |
| apache_software_foundation | apache_xalan-j | Xalan-J – 2.7.2 | — |
| atlassian | jira_software | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| debian | bcel | < bcel 6.5.0-2 (bookworm) | bcel 6.5.0-2 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-11 | < bcel 6.5.0-2 (bookworm) | bcel 6.5.0-2 (bookworm) |
| debian | openjdk-17 | < bcel 6.5.0-2 (bookworm) | bcel 6.5.0-2 (bookworm) |
| debian | openjdk-8 | < bcel 6.5.0-2 (bookworm) | bcel 6.5.0-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_python-tensorboard_2.16.2-6_on_azure_linux_3.0 | — | — |
| msrc | cm1_openjdk8_1.8.0.332-2_on_cbl_mariner_1.0 | — | — |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
| oracle | jdk | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: malicious XSLT stylesheets processed by Apache Xalan Java XSLTC compiler cause integer truncation, corrupting generated Java class files to execute arbitrary bytecode ↗
- →Remote exploitation is possible over HTTP; treat any externally-supplied XSLT stylesheet input to Xalan-based services as a potential attack vector ↗
- →Affected component is the xalan:xalan dependency (Apache Xalan-Java); audit Java applications (including Jira Software Data Center/Server) for inclusion of this library ↗
- →Note that Java runtimes such as OpenJDK ship repackaged copies of Xalan; scan JRE/JDK installations as well as application dependencies for vulnerable versions (fix: Xalan 2.7.3+) ↗
- ·Debian-based systems: vulnerability is resolved in specific package versions per release — bookworm/forky/sid/trixie fixed in 6.5.0-2, bullseye fixed in 6.5.0-1+deb11u1 ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Mathematical Operators (Apache Xalan-Java) — CVE-2022-34169
vendor_oracle·2025-07-15·CVSS 7.5
CVE-2022-34169 [HIGH] Oracle Oracle Retail Applications Risk Matrix: Mathematical Operators (Apache Xalan-Java) — CVE-2022-34169
Oracle Oracle Retail Applications Risk Matrix: Mathematical Operators (Apache Xalan-Java) vulnerability
CVE: CVE-2022-34169
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Xalan-Java) — CVE-2022-34169
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2022-34169 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Xalan-Java) — CVE-2022-34169
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Xalan-Java) vulnerability
CVE: CVE-2022-34169
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Commerce Risk Matrix: Workbench, Content Acquisition System, Platform Services (Apache Xalan-Java) — CVE-2022-34169
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2022-34169 [HIGH] Oracle Oracle Commerce Risk Matrix: Workbench, Content Acquisition System, Platform Services (Apache Xalan-Java) — CVE-2022-34169
Oracle Oracle Commerce Risk Matrix: Workbench, Content Acquisition System, Platform Services (Apache Xalan-Java) vulnerability
CVE: CVE-2022-34169
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: General (Apache Xalan-Java) — CVE-2022-34169
vendor_oracle·2024-04-15·CVSS 7.5
CVE-2022-34169 [HIGH] Oracle Oracle Communications Applications Risk Matrix: General (Apache Xalan-Java) — CVE-2022-34169
Oracle Oracle Communications Applications Risk Matrix: General (Apache Xalan-Java) vulnerability
CVE: CVE-2022-34169
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Atlassian
CVE-2022-34169: RCE (Remote Code Execution) xalan:xalan Dependency in Jira Software Data Center and Server
vendor_atlassian·2024-03-19·CVSS 7.5
CVE-2022-34169 [HIGH] CVE-2022-34169: RCE (Remote Code Execution) xalan:xalan Dependency in Jira Software Data Center and Server
CVE-2022-34169: RCE (Remote Code Execution) xalan:xalan Dependency in Jira Software Data Center and Server
RCE (Remote Code Execution) xalan:xalan Dependency in Jira Software Data Center and Server
CVE: CVE-2022-34169
Affected products: Jira Software
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Web UI (Oracle Java SE) — CVE-2022-34169
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2022-34169 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Web UI (Oracle Java SE) — CVE-2022-34169
Oracle Oracle Financial Services Applications Risk Matrix: Web UI (Oracle Java SE) vulnerability
CVE: CVE-2022-34169
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Xalan-Java) — CVE-2022-34169
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-34169 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Xalan-Java) — CVE-2022-34169
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Xalan-Java) vulnerability
CVE: CVE-2022-34169
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Supply Chain Risk Matrix: Application Server (Apache Xalan-J) — CVE-2022-34169
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-34169 [HIGH] Oracle Oracle Supply Chain Risk Matrix: Application Server (Apache Xalan-J) — CVE-2022-34169
Oracle Oracle Supply Chain Risk Matrix: Application Server (Apache Xalan-J) vulnerability
CVE: CVE-2022-34169
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2022-08-04·CVSS 5.3
CVE-2022-21434 [MEDIUM] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
USN-5546-1 fixed vulnerabilities in OpenJDK.
This update provides the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
Neil Madden discovered that OpenJDK did not properly verify ECDSA
signatures. A remote attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected OpenJDK
17 and OpenJDK 18. (CVE-2022-21449)
It was discovered that OpenJDK incorrectly limited memory when compiling a
specially crafted XPath expression. An attacker could possibly use this
issue to cause a denial of service. This issue was fixed in OpenJDK 8 and
OpenJDK 18. USN-5388-1 and USN-5388-2 addressed this issue in OpenJDK 11
and OpenJDK 17. (CVE-2022
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2022-08-04·CVSS 5.3
CVE-2022-21541 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Neil Madden discovered that OpenJDK did not properly verify ECDSA
signatures. A remote attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected OpenJDK
17 and OpenJDK 18. (CVE-2022-21449)
It was discovered that OpenJDK incorrectly limited memory when compiling a
specially crafted XPath expression. An attacker could possibly use this
issue to cause a denial of service. This issue was fixed in OpenJDK 8 and
OpenJDK 18. USN-5388-1 and USN-5388-2 addressed this issue in OpenJDK 11
and OpenJDK 17. (CVE-2022-21426)
It was discovered that OpenJDK incorrectly handled converting certain
object arguments into their textual representations. An attacker cou
Red Hat
OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407)
vendor_redhat·2022-07-19·CVSS 7.5
CVE-2022-34169 [HIGH] CWE-192 OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407)
OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407)
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
Package: xalan (Migration Toolkit for Applications 6) - Will not fix
Package: xalan (Migration Toolkit for Runtimes) - Not affected
Package: xalan (Red Hat AMQ Broker 7) - Not affected
Package: xalan (Red Hat build of Apache Camel 4 for Quarkus 3) - Affected
Package: xalan (Red Hat build of Apache Camel for Spring Boot 3) - Affected
Package: xalan (R
Oracle
Oracle Oracle Java SE Risk Matrix: JAXP (Xalan-J) — CVE-2022-34169
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2022-34169 [HIGH] Oracle Oracle Java SE Risk Matrix: JAXP (Xalan-J) — CVE-2022-34169
Oracle Oracle Java SE Risk Matrix: JAXP (Xalan-J) vulnerability
CVE: CVE-2022-34169
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Microsoft
Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
vendor_msrc·2022-07-12·CVSS 7.5
CVE-2022-34169 [HIGH] CWE-681 Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required:
Debian
CVE-2022-34169: bcel - The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue ...
vendor_debian·2022·CVSS 7.5
CVE-2022-34169 [HIGH] CVE-2022-34169: bcel - The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue ...
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
Scope: local
bookworm: resolved (fixed in 6.5.0-2)
bullseye: resolved (fixed in 6.5.0-1+deb11u1)
forky: resolved (fixed in 6.5.0-2)
sid: resolved (fixed in 6.5.0-2)
trixie: resolved (fixed in 6.5.0-2)
Project0
Gregor Samsa: Exploiting Java's XML Signature Verification - Project Zero
project_zero·2022-11-01·CVSS 7.5
CVE-2022-34169 [HIGH] Gregor Samsa: Exploiting Java's XML Signature Verification - Project Zero
By Felix Wilhelm, Project Zero
Earlier this year, I discovered a surprising attack surface hidden deep inside Java’s standard library: A custom JIT compiler processing untrusted XSLT programs, exposed to remote attackers during XML signature verification. This post discusses CVE-2022-34169, an integer truncation bug in this JIT compiler resulting in arbitrary code execution in many Java-based web applications and identity providers that support the SAML single-sign-on standard.
OpenJDK fixed the discussed issue in July 2022. The Apache BCEL project used by Xalan-J, the origin of the vulnerable code, released a patch in September 2022.
While the vulnerability discussed in this post has been patched , vendors and users should expect further vulnerabilities in SAML.
From a security res
OSV
openjdk-8, openjdk-lts, openjdk-17, openjdk-18 vulnerabilities
osv·2022-08-04·CVSS 5.3
CVE-2022-21449 [MEDIUM] openjdk-8, openjdk-lts, openjdk-17, openjdk-18 vulnerabilities
openjdk-8, openjdk-lts, openjdk-17, openjdk-18 vulnerabilities
Neil Madden discovered that OpenJDK did not properly verify ECDSA
signatures. A remote attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected OpenJDK
17 and OpenJDK 18. (CVE-2022-21449)
It was discovered that OpenJDK incorrectly limited memory when compiling a
specially crafted XPath expression. An attacker could possibly use this
issue to cause a denial of service. This issue was fixed in OpenJDK 8 and
OpenJDK 18. USN-5388-1 and USN-5388-2 addressed this issue in OpenJDK 11
and OpenJDK 17. (CVE-2022-21426)
It was discovered that OpenJDK incorrectly handled converting certain
object arguments into their textual representations. An attacker could
possibly use this issu
OSV
openjdk-8 vulnerabilities
osv·2022-08-04·CVSS 5.3
CVE-2022-21449 [MEDIUM] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
USN-5546-1 fixed vulnerabilities in OpenJDK.
This update provides the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
Neil Madden discovered that OpenJDK did not properly verify ECDSA
signatures. A remote attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected OpenJDK
17 and OpenJDK 18. (CVE-2022-21449)
It was discovered that OpenJDK incorrectly limited memory when compiling a
specially crafted XPath expression. An attacker could possibly use this
issue to cause a denial of service. This issue was fixed in OpenJDK 8 and
OpenJDK 18. USN-5388-1 and USN-5388-2 addressed this issue in OpenJDK 11
and OpenJDK 17. (CVE-2022-21426)
It was discovered that OpenJDK incorrectly handled conver
OSV
Apache Xalan Java XSLT library integer truncation issue when processing malicious XSLT stylesheets
osv·2022-07-20
CVE-2022-34169 [HIGH] Apache Xalan Java XSLT library integer truncation issue when processing malicious XSLT stylesheets
Apache Xalan Java XSLT library integer truncation issue when processing malicious XSLT stylesheets
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode.
A fix for this issue was published in September 2022 as part of an anticipated 2.7.3 release.
GHSA
Apache Xalan Java XSLT library integer truncation issue when processing malicious XSLT stylesheets
ghsa·2022-07-20
CVE-2022-34169 [HIGH] CWE-681 Apache Xalan Java XSLT library integer truncation issue when processing malicious XSLT stylesheets
Apache Xalan Java XSLT library integer truncation issue when processing malicious XSLT stylesheets
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode.
A fix for this issue was published in September 2022 as part of an anticipated 2.7.3 release.
OSV
CVE-2022-34169: The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
osv·2022-07-19·CVSS 7.5
CVE-2022-34169 [HIGH] CVE-2022-34169: The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/168186/Xalan-J-XSLTC-Integer-Truncation.htmlhttp://www.openwall.com/lists/oss-security/2022/07/19/5http://www.openwall.com/lists/oss-security/2022/07/19/6http://www.openwall.com/lists/oss-security/2022/07/20/2http://www.openwall.com/lists/oss-security/2022/07/20/3http://www.openwall.com/lists/oss-security/2022/10/18/2http://www.openwall.com/lists/oss-security/2022/11/04/8http://www.openwall.com/lists/oss-security/2022/11/07/2https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kywhttps://lists.apache.org/thread/2qvl7r43wb4t8p9dd9om1bnkssk07sn8https://lists.debian.org/debian-lts-announce/2022/10/msg00024.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB/https://security.gentoo.org/glsa/202401-25https://security.netapp.com/advisory/ntap-20220729-0009/https://security.netapp.com/advisory/ntap-20240621-0006/https://www.debian.org/security/2022/dsa-5188https://www.debian.org/security/2022/dsa-5192https://www.debian.org/security/2022/dsa-5256https://www.oracle.com/security-alerts/cpujul2022.htmlhttp://packetstormsecurity.com/files/168186/Xalan-J-XSLTC-Integer-Truncation.htmlhttp://www.openwall.com/lists/oss-security/2022/07/19/5http://www.openwall.com/lists/oss-security/2022/07/19/6http://www.openwall.com/lists/oss-security/2022/07/20/2http://www.openwall.com/lists/oss-security/2022/07/20/3http://www.openwall.com/lists/oss-security/2022/10/18/2http://www.openwall.com/lists/oss-security/2022/11/04/8http://www.openwall.com/lists/oss-security/2022/11/07/2https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kywhttps://lists.apache.org/thread/2qvl7r43wb4t8p9dd9om1bnkssk07sn8https://lists.debian.org/debian-lts-announce/2022/10/msg00024.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB/https://security.gentoo.org/glsa/202401-25https://security.netapp.com/advisory/ntap-20220729-0009/https://security.netapp.com/advisory/ntap-20240621-0006/https://www.debian.org/security/2022/dsa-5188https://www.debian.org/security/2022/dsa-5192https://www.debian.org/security/2022/dsa-5256https://www.oracle.com/security-alerts/cpujul2022.html
2022-07-19
Published