CVE-2022-21299: Medium severity IBM Cognos Analytics vulnerability
A flaw was found in the way the XMLEntityScanner and XML11EntityScanner classes in the JAXP component of OpenJDK handled and normalized newlines in XML entities. A specially-crafted XML document could cause a Java application to enter an infinite loop when parsed.
Other sources
An unspecified vulnerability in Java SE related to the JAXP component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
— IBM
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-1:11.0.14.0.9-1.el7_9 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.5.10-1jpp.1.el7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-1:17.0.2.0.8-4.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-1:11.0.14.0.9-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.322.b06-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-1:11.0.14.0.9-1.el8_1 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.322.b06-1.el8_1 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-1:11.0.14.0.9-1.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.322.b06-1.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-1:11.0.14.0.9-2.el8_4 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.322.b06-2.el8_4 - Upgrade
Upgrade
redhat/eap7-xerces-j2to a version that resolves this vulnerability.Fixed in 0:2.12.0-3.SP04_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-xerces-j2to a version that resolves this vulnerability.Fixed in 0:2.12.0-3.SP04_redhat_00001.1.el7ea - Upgrade
Upgrade
debian/openjdk-11to a version that resolves this vulnerability.Fixed in 11.0.16+8-1~deb10u1Fixed in 11.0.21+9-1~deb10u1Fixed in 11.0.20+8-1~deb11u1Fixed in 11.0.21+9-1~deb11u1Fixed in 11.0.22~6ea-1 - Upgrade
Upgrade
debian/openjdk-17to a version that resolves this vulnerability.Fixed in 17.0.7+7-1~deb11u1Fixed in 17.0.9+9-1~deb11u1Fixed in 17.0.9+9-1~deb12u1Fixed in 17.0.9+9-2Fixed in 17.0.10~6ea-1 - Upgrade
Upgrade
debian/openjdk-8to a version that resolves this vulnerability.Fixed in 8u392-ga-1 - Upgrade
Upgrade
OpenJDK JAXP (XMLEntityScanner/XML11EntityScanner)to a version that resolves this vulnerability.Fixed in 7u321 - Upgrade
Upgrade
OpenJDK JAXP (XMLEntityScanner/XML11EntityScanner)to a version that resolves this vulnerability.Fixed in 8u311 - Upgrade
Upgrade
OpenJDK JAXP (XMLEntityScanner/XML11EntityScanner)to a version that resolves this vulnerability.Fixed in 11.0.13 - Upgrade
Upgrade
OpenJDK JAXP (XMLEntityScanner/XML11EntityScanner)to a version that resolves this vulnerability.Fixed in 17.0.1 - Upgrade
Upgrade
Oracle GraalVM Enterprise Edition JAXP (XMLEntityScanner/XML11EntityScanner)to a version that resolves this vulnerability.Fixed in 20.3.4 - Upgrade
Upgrade
Oracle GraalVM Enterprise Edition JAXP (XMLEntityScanner/XML11EntityScanner)to a version that resolves this vulnerability.Fixed in 21.3.0 - Compensating control
Run Java deployments (Oracle Java SE / Oracle GraalVM Enterprise Edition) that use the Java sandbox only with untrusted code sources controlled (e.g., avoid loading untrusted XML/data over the network into JAXP-based parsing APIs).
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:0229
- RHSA-2022:0166
- RHSA-2022:0165
- RHSA-2022:0317
- RHSA-2022:0321
- RHSA-2022:0204
- RHSA-2022:0306
- RHSA-2022:4957
- RHSA-2022:0161
- RHSA-2022:0185
- RHSA-2022:0307
- RHSA-2022:0233
- RHSA-2022:0304
- RHSA-2022:0209
- RHSA-2022:0305
- RHSA-2022:0211
- RHSA-2022:0312
- RHSA-2022:4922
- RHSA-2022:4919
- RHSA-2022:4918
- RHSA-2022:0228
- IBM-7123154
Frequently Asked Questions
What is the severity of CVE-2022-21299?
CVE-2022-21299 is characterized as a high-severity vulnerability due to its potential to cause an infinite loop in applications that process specially-crafted XML documents.
How do I fix CVE-2022-21299?
To fix CVE-2022-21299, you should apply the latest patches available for affected versions of OpenJDK, specifically versions 1.7, 1.8, 11, and 17.
What types of software are affected by CVE-2022-21299?
CVE-2022-21299 affects various builds of OpenJDK including versions from Red Hat and Oracle, as well as related distributions such as IBM Cognos Analytics.
How does CVE-2022-21299 impact Java applications?
CVE-2022-21299 can lead Java applications that parse certain XML documents into an infinite loop, potentially causing denial of service.
Is CVE-2022-21299 related to any other vulnerabilities?
While CVE-2022-21299 is a distinct vulnerability, its issues surrounding XML parsing may have similarities to other XML-related vulnerabilities in Java.