First published: Mon Jan 17 2022(Updated: )
A flaw was found in the way the XMLEntityScanner and XML11EntityScanner classes in the JAXP component of OpenJDK handled and normalized newlines in XML entities. A specially-crafted XML document could cause a Java application to enter an infinite loop when parsed.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <11-openjdk-1:11.0.14.0.9-1.el7_9 | 11-openjdk-1:11.0.14.0.9-1.el7_9 |
redhat/java | <1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9 | 1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9 |
redhat/java | <1.7.1-ibm-1:1.7.1.5.10-1jpp.1.el7 | 1.7.1-ibm-1:1.7.1.5.10-1jpp.1.el7 |
redhat/java | <17-openjdk-1:17.0.2.0.8-4.el8_5 | 17-openjdk-1:17.0.2.0.8-4.el8_5 |
redhat/java | <11-openjdk-1:11.0.14.0.9-2.el8_5 | 11-openjdk-1:11.0.14.0.9-2.el8_5 |
redhat/java | <1.8.0-openjdk-1:1.8.0.322.b06-2.el8_5 | 1.8.0-openjdk-1:1.8.0.322.b06-2.el8_5 |
redhat/java | <11-openjdk-1:11.0.14.0.9-1.el8_1 | 11-openjdk-1:11.0.14.0.9-1.el8_1 |
redhat/java | <1.8.0-openjdk-1:1.8.0.322.b06-1.el8_1 | 1.8.0-openjdk-1:1.8.0.322.b06-1.el8_1 |
redhat/java | <11-openjdk-1:11.0.14.0.9-1.el8_2 | 11-openjdk-1:11.0.14.0.9-1.el8_2 |
redhat/java | <1.8.0-openjdk-1:1.8.0.322.b06-1.el8_2 | 1.8.0-openjdk-1:1.8.0.322.b06-1.el8_2 |
redhat/java | <11-openjdk-1:11.0.14.0.9-2.el8_4 | 11-openjdk-1:11.0.14.0.9-2.el8_4 |
redhat/java | <1.8.0-openjdk-1:1.8.0.322.b06-2.el8_4 | 1.8.0-openjdk-1:1.8.0.322.b06-2.el8_4 |
redhat/eap7-xerces-j2 | <0:2.12.0-3.SP04_redhat_00001.1.el8ea | 0:2.12.0-3.SP04_redhat_00001.1.el8ea |
redhat/eap7-xerces-j2 | <0:2.12.0-3.SP04_redhat_00001.1.el7ea | 0:2.12.0-3.SP04_redhat_00001.1.el7ea |
debian/openjdk-11 | 11.0.16+8-1~deb10u1 11.0.21+9-1~deb10u1 11.0.20+8-1~deb11u1 11.0.21+9-1~deb11u1 11.0.22~6ea-1 | |
debian/openjdk-17 | 17.0.7+7-1~deb11u1 17.0.9+9-1~deb11u1 17.0.9+9-1~deb12u1 17.0.9+9-2 17.0.10~6ea-1 | |
debian/openjdk-8 | 8u392-ga-1 | |
IBM Cognos Analytics | <=12.0.0-12.0.1 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP2 | |
IBM Cognos Analytics | <=11.1.1-11.1.7 FP7 | |
Oracle GraalVM Enterprise Edition | =20.3.4 | |
Oracle GraalVM Enterprise Edition | =21.3.0 | |
Oracle JDK 6 | =1.7.0-update321 | |
Oracle JDK 6 | =1.8.0-update311 | |
Oracle JDK 6 | =11.0.13 | |
Oracle JDK 6 | =17.0.1 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update321 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update311 | |
Oracle Java Runtime Environment (JRE) | =11.0.13 | |
Oracle Java Runtime Environment (JRE) | =17.0.1 | |
NetApp 7-Mode Transition Tool | ||
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp active iq unified manager windows | ||
netapp cloud insights acquisition unit | ||
netapp cloud secure agent | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.1 | |
netapp e-series santricity storage manager | ||
netapp e-series santricity Web services Web services proxy | ||
netapp hci management node | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp SANtricity Storage Plugin for vCenter | ||
netapp santricity unified manager | ||
netapp snapmanager Oracle | ||
netapp snapmanager sap | ||
netapp solidfire | ||
Debian | =9.0 | |
Debian | =10.0 | |
Debian | =11.0 | |
OpenJDK 17 | >=11<=11.0.13 | |
OpenJDK 17 | >=13<=13.0.9 | |
OpenJDK 17 | >=15<=15.0.5 | |
OpenJDK 17 | =7 | |
OpenJDK 17 | =7-update1 | |
OpenJDK 17 | =7-update10 | |
OpenJDK 17 | =7-update101 | |
OpenJDK 17 | =7-update11 | |
OpenJDK 17 | =7-update111 | |
OpenJDK 17 | =7-update121 | |
OpenJDK 17 | =7-update13 | |
OpenJDK 17 | =7-update131 | |
OpenJDK 17 | =7-update141 | |
OpenJDK 17 | =7-update15 | |
OpenJDK 17 | =7-update151 | |
OpenJDK 17 | =7-update161 | |
OpenJDK 17 | =7-update17 | |
OpenJDK 17 | =7-update171 | |
OpenJDK 17 | =7-update181 | |
OpenJDK 17 | =7-update191 | |
OpenJDK 17 | =7-update2 | |
OpenJDK 17 | =7-update201 | |
OpenJDK 17 | =7-update21 | |
OpenJDK 17 | =7-update211 | |
OpenJDK 17 | =7-update221 | |
OpenJDK 17 | =7-update231 | |
OpenJDK 17 | =7-update241 | |
OpenJDK 17 | =7-update25 | |
OpenJDK 17 | =7-update251 | |
OpenJDK 17 | =7-update261 | |
OpenJDK 17 | =7-update271 | |
OpenJDK 17 | =7-update281 | |
OpenJDK 17 | =7-update291 | |
OpenJDK 17 | =7-update3 | |
OpenJDK 17 | =7-update301 | |
OpenJDK 17 | =7-update311 | |
OpenJDK 17 | =7-update321 | |
OpenJDK 17 | =7-update4 | |
OpenJDK 17 | =7-update40 | |
OpenJDK 17 | =7-update45 | |
OpenJDK 17 | =7-update5 | |
OpenJDK 17 | =7-update51 | |
OpenJDK 17 | =7-update55 | |
OpenJDK 17 | =7-update6 | |
OpenJDK 17 | =7-update60 | |
OpenJDK 17 | =7-update65 | |
OpenJDK 17 | =7-update67 | |
OpenJDK 17 | =7-update7 | |
OpenJDK 17 | =7-update72 | |
OpenJDK 17 | =7-update76 | |
OpenJDK 17 | =7-update80 | |
OpenJDK 17 | =7-update85 | |
OpenJDK 17 | =7-update9 | |
OpenJDK 17 | =7-update91 | |
OpenJDK 17 | =7-update95 | |
OpenJDK 17 | =7-update97 | |
OpenJDK 17 | =7-update99 | |
OpenJDK 17 | =8 | |
OpenJDK 17 | =8-milestone1 | |
OpenJDK 17 | =8-milestone2 | |
OpenJDK 17 | =8-milestone3 | |
OpenJDK 17 | =8-milestone4 | |
OpenJDK 17 | =8-milestone5 | |
OpenJDK 17 | =8-milestone6 | |
OpenJDK 17 | =8-milestone7 | |
OpenJDK 17 | =8-milestone8 | |
OpenJDK 17 | =8-milestone9 | |
OpenJDK 17 | =8-update101 | |
OpenJDK 17 | =8-update102 | |
OpenJDK 17 | =8-update11 | |
OpenJDK 17 | =8-update111 | |
OpenJDK 17 | =8-update112 | |
OpenJDK 17 | =8-update121 | |
OpenJDK 17 | =8-update131 | |
OpenJDK 17 | =8-update141 | |
OpenJDK 17 | =8-update151 | |
OpenJDK 17 | =8-update152 | |
OpenJDK 17 | =8-update161 | |
OpenJDK 17 | =8-update162 | |
OpenJDK 17 | =8-update171 | |
OpenJDK 17 | =8-update172 | |
OpenJDK 17 | =8-update181 | |
OpenJDK 17 | =8-update191 | |
OpenJDK 17 | =8-update192 | |
OpenJDK 17 | =8-update20 | |
OpenJDK 17 | =8-update201 | |
OpenJDK 17 | =8-update202 | |
OpenJDK 17 | =8-update211 | |
OpenJDK 17 | =8-update212 | |
OpenJDK 17 | =8-update221 | |
OpenJDK 17 | =8-update222 | |
OpenJDK 17 | =8-update231 | |
OpenJDK 17 | =8-update232 | |
OpenJDK 17 | =8-update241 | |
OpenJDK 17 | =8-update242 | |
OpenJDK 17 | =8-update25 | |
OpenJDK 17 | =8-update252 | |
OpenJDK 17 | =8-update262 | |
OpenJDK 17 | =8-update271 | |
OpenJDK 17 | =8-update281 | |
OpenJDK 17 | =8-update282 | |
OpenJDK 17 | =8-update291 | |
OpenJDK 17 | =8-update301 | |
OpenJDK 17 | =8-update302 | |
OpenJDK 17 | =8-update31 | |
OpenJDK 17 | =8-update312 | |
OpenJDK 17 | =8-update40 | |
OpenJDK 17 | =8-update45 | |
OpenJDK 17 | =8-update5 | |
OpenJDK 17 | =8-update51 | |
OpenJDK 17 | =8-update60 | |
OpenJDK 17 | =8-update65 | |
OpenJDK 17 | =8-update66 | |
OpenJDK 17 | =8-update71 | |
OpenJDK 17 | =8-update72 | |
OpenJDK 17 | =8-update73 | |
OpenJDK 17 | =8-update74 | |
OpenJDK 17 | =8-update77 | |
OpenJDK 17 | =8-update91 | |
OpenJDK 17 | =8-update92 | |
OpenJDK 17 | =17 | |
OpenJDK 17 | =17.0.1 | |
netapp cloud insights |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-21299 is characterized as a high-severity vulnerability due to its potential to cause an infinite loop in applications that process specially-crafted XML documents.
To fix CVE-2022-21299, you should apply the latest patches available for affected versions of OpenJDK, specifically versions 1.7, 1.8, 11, and 17.
CVE-2022-21299 affects various builds of OpenJDK including versions from Red Hat and Oracle, as well as related distributions such as IBM Cognos Analytics.
CVE-2022-21299 can lead Java applications that parse certain XML documents into an infinite loop, potentially causing denial of service.
While CVE-2022-21299 is a distinct vulnerability, its issues surrounding XML parsing may have similarities to other XML-related vulnerabilities in Java.