First published: Mon Jan 24 2022(Updated: )
Apache Xerces2 Java XML Parser is vulnerable to a denial of service, caused by an infinite loop in the XML parser. By persuading a victim to open a specially-crafted XML document payloads, a remote attacker could exploit this vulnerability to consume system resources for prolonged duration.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-xerces-j2 | <0:2.12.0-3.SP04_redhat_00001.1.el8ea | 0:2.12.0-3.SP04_redhat_00001.1.el8ea |
redhat/eap7-xerces-j2 | <0:2.12.0-3.SP04_redhat_00001.1.el7ea | 0:2.12.0-3.SP04_redhat_00001.1.el7ea |
redhat/xerces-j2 | <2.12.2 | 2.12.2 |
IBM Sterling Secure Proxy | <=6.0.3 | |
Apache Xalan-Java | <=2.12.1 | |
Oracle Agile Engineering Data Management | =6.2.1.0 | |
Oracle Agile PLM | =9.3.6 | |
Oracle Banking Deposits and Lines of Credit Servicing | =2.7 | |
Oracle Banking Party Management | =2.7.0 | |
Oracle Communications ASAP | =7.3 | |
oracle communications element manager | <9.0 | |
oracle communications session report manager | <9.0 | |
oracle communications session route manager | <9.0 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.0.6.0.0<=8.0.9.0 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.1.0.0<8.1.2.0 | |
Oracle Financial Services Behavior Detection Platform | >=8.0.6.0.0<=8.0.8.0 | |
Oracle Financial Services Behavior Detection Platform | =8.1.1.0 | |
Oracle Financial Services Behavior Detection Platform | =8.1.1.1 | |
Oracle Financial Services Behavior Detection Platform | =8.1.2.0 | |
Oracle Financial Services Crime and Compliance Management Studio | =8.0.8.2.0 | |
Oracle Financial Services Crime and Compliance Management Studio | =8.0.8.3.0 | |
Oracle Financial Services Enterprise Case Management | =8.0.7.1 | |
Oracle Financial Services Enterprise Case Management | =8.0.7.2.0 | |
Oracle Financial Services Enterprise Case Management | =8.0.8.0 | |
Oracle Financial Services Enterprise Case Management | =8.0.8.1 | |
Oracle Financial Services Enterprise Case Management | =8.1.1.0 | |
Oracle Financial Services Enterprise Case Management | =8.1.1.1 | |
Oracle FLEXCUBE Universal Banking | =12.4.0 | |
Oracle Global Lifecycle Management NextGen OUI Framework | <13.9.4.2.2 | |
Oracle Global Lifecycle Management NextGen OUI Framework | =13.9.4.2.2 | |
oracle global lifecycle management opatch | <12.2.0.1.30 | |
Oracle Health Sciences Information Manager | >=3.0.1<=3.0.5 | |
Oracle Health Sciences Information Manager | =3.0.0.1 | |
Oracle Hyperion iLearning | =6.2 | |
Oracle Hyperion iLearning | =6.3 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.59 | |
oracle primavera gateway | >=17.7<=17.12.11 | |
oracle primavera gateway | >=18.8.0<=18.8.14 | |
oracle primavera gateway | >=19.12.0<=19.12.13 | |
oracle primavera gateway | >=20.12.0<=20.12.8 | |
oracle product lifecycle analytics | =3.6.1 | |
Oracle Retail Bulk Data Integration | =16.0.3.0 | |
Oracle Retail Extract Transform And Load | =13.2.8 | |
oracle retail financial integration | =14.1.3.2 | |
oracle retail financial integration | =15.0.3.1 | |
oracle retail financial integration | =16.0.3 | |
oracle retail financial integration | =19.0.1 | |
Oracle Retail Integration Bus | =14.1.3.2 | |
Oracle Retail Integration Bus | =15.0.3.1 | |
Oracle Retail Integration Bus | =16.0.3 | |
Oracle Retail Integration Bus | =19.0.1 | |
Oracle Retail Merchandising System | =16.0.3 | |
Oracle Retail Merchandising System | =19.0.1 | |
Oracle Retail Service Backbone | =14.1.3.2 | |
Oracle Retail Service Backbone | =15.0.3.1 | |
Oracle Retail Service Backbone | =16.0.3 | |
Oracle Retail Service Backbone | =19.0.1 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 | |
Oracle WebLogic Server | =14.1.1.0.0 | |
netapp active iq unified manager windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-23437 is classified as a denial of service vulnerability.
To mitigate CVE-2022-23437, update Apache Xerces-J to versions 2.12.2 or higher, or apply the relevant patches from your software vendor.
CVE-2022-23437 affects Apache Xerces-J up to version 2.12.1.
Yes, CVE-2022-23437 can be exploited remotely by convincing a user to open a specially-crafted XML document.
Applications using vulnerable versions of Apache Xerces-J, including various Oracle and IBM products, are susceptible to CVE-2022-23437.