cbcvebase.
CVE-2022-34169
published 2022-07-19

CVE-2022-34169: The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java…

PriorityP265high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
81.04%
99.6th percentile
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
apachexalan-java<= 2.7.2
apache_software_foundationapache_xalan-jXalan-J – 2.7.2
atlassianjira_software
azulzulu
azulzulu
azulzulu
azulzulu
azulzulu
azulzulu
azulzulu
azulzulu
debianbcel< bcel 6.5.0-2 (bookworm)bcel 6.5.0-2 (bookworm)
debiandebian_linux
debiandebian_linux
debianopenjdk-11< bcel 6.5.0-2 (bookworm)bcel 6.5.0-2 (bookworm)
debianopenjdk-17< bcel 6.5.0-2 (bookworm)bcel 6.5.0-2 (bookworm)
debianopenjdk-8< bcel 6.5.0-2 (bookworm)bcel 6.5.0-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_python-tensorboard_2.16.2-6_on_azure_linux_3.0
msrccm1_openjdk8_1.8.0.332-2_on_cbl_mariner_1.0
oraclegraalvm
oraclegraalvm
oraclegraalvm
oraclejdk

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: malicious XSLT stylesheets processed by Apache Xalan Java XSLTC compiler cause integer truncation, corrupting generated Java class files to execute arbitrary bytecode
  • Remote exploitation is possible over HTTP; treat any externally-supplied XSLT stylesheet input to Xalan-based services as a potential attack vector
  • Affected component is the xalan:xalan dependency (Apache Xalan-Java); audit Java applications (including Jira Software Data Center/Server) for inclusion of this library
  • Note that Java runtimes such as OpenJDK ship repackaged copies of Xalan; scan JRE/JDK installations as well as application dependencies for vulnerable versions (fix: Xalan 2.7.3+)
  • ·Debian-based systems: vulnerability is resolved in specific package versions per release — bookworm/forky/sid/trixie fixed in 6.5.0-2, bullseye fixed in 6.5.0-1+deb11u1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.