First published: Mon Jan 24 2022(Updated: )
Apache Xerces2 Java XML Parser is vulnerable to a denial of service, caused by an infinite loop in the XML parser. By persuading a victim to open a specially-crafted XML document payloads, a remote attacker could exploit this vulnerability to consume system resources for prolonged duration.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-xerces-j2 | <0:2.12.0-3.SP04_redhat_00001.1.el8ea | 0:2.12.0-3.SP04_redhat_00001.1.el8ea |
redhat/eap7-xerces-j2 | <0:2.12.0-3.SP04_redhat_00001.1.el7ea | 0:2.12.0-3.SP04_redhat_00001.1.el7ea |
IBM Sterling Secure Proxy | <=6.0.3 | |
redhat/xerces-j2 | <2.12.2 | 2.12.2 |
Apache Xerces-j | <=2.12.1 | |
Oracle Agile Engineering Data Management | =6.2.1.0 | |
Oracle Agile PLM | =9.3.6 | |
Oracle Banking Deposits And Lines Of Credit Servicing | =2.7 | |
Oracle Banking Party Management | =2.7.0 | |
Oracle Communications Asap | =7.3 | |
Oracle Communications Element Manager | <9.0 | |
Oracle Communications Session Report Manager | <9.0 | |
Oracle Communications Session Route Manager | <9.0 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.0.6.0.0<=8.0.9.0 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.1.0.0<8.1.2.0 | |
Oracle Financial Services Behavior Detection Platform | >=8.0.6.0.0<=8.0.8.0 | |
Oracle Financial Services Behavior Detection Platform | =8.1.1.0 | |
Oracle Financial Services Behavior Detection Platform | =8.1.1.1 | |
Oracle Financial Services Behavior Detection Platform | =8.1.2.0 | |
Oracle Financial Services Crime And Compliance Management Studio | =8.0.8.2.0 | |
Oracle Financial Services Crime And Compliance Management Studio | =8.0.8.3.0 | |
Oracle Financial Services Enterprise Case Management | =8.0.7.1 | |
Oracle Financial Services Enterprise Case Management | =8.0.7.2.0 | |
Oracle Financial Services Enterprise Case Management | =8.0.8.0 | |
Oracle Financial Services Enterprise Case Management | =8.0.8.1 | |
Oracle Financial Services Enterprise Case Management | =8.1.1.0 | |
Oracle Financial Services Enterprise Case Management | =8.1.1.1 | |
Oracle FLEXCUBE Universal Banking | =12.4.0 | |
Oracle Global Lifecycle Management NextGen OUI Framework | <13.9.4.2.2 | |
Oracle Global Lifecycle Management NextGen OUI Framework | =13.9.4.2.2 | |
Oracle Global Lifecycle Management Opatch | <12.2.0.1.30 | |
Oracle Health Sciences Information Manager | >=3.0.1<=3.0.5 | |
Oracle Health Sciences Information Manager | =3.0.0.1 | |
Oracle iLearning | =6.2 | |
Oracle iLearning | =6.3 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.59 | |
Oracle Primavera Gateway | >=17.7<=17.12.11 | |
Oracle Primavera Gateway | >=18.8.0<=18.8.14 | |
Oracle Primavera Gateway | >=19.12.0<=19.12.13 | |
Oracle Primavera Gateway | >=20.12.0<=20.12.8 | |
Oracle Product Lifecycle Analytics | =3.6.1 | |
Oracle Retail Bulk Data Integration | =16.0.3.0 | |
Oracle Retail Extract Transform And Load | =13.2.8 | |
Oracle Retail Financial Integration | =14.1.3.2 | |
Oracle Retail Financial Integration | =15.0.3.1 | |
Oracle Retail Financial Integration | =16.0.3 | |
Oracle Retail Financial Integration | =19.0.1 | |
Oracle Retail Integration Bus | =14.1.3.2 | |
Oracle Retail Integration Bus | =15.0.3.1 | |
Oracle Retail Integration Bus | =16.0.3 | |
Oracle Retail Integration Bus | =19.0.1 | |
Oracle Retail Merchandising System | =16.0.3 | |
Oracle Retail Merchandising System | =19.0.1 | |
Oracle Retail Service Backbone | =14.1.3.2 | |
Oracle Retail Service Backbone | =15.0.3.1 | |
Oracle Retail Service Backbone | =16.0.3 | |
Oracle Retail Service Backbone | =19.0.1 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 | |
Oracle WebLogic Server | =14.1.1.0.0 | |
Netapp Active Iq Unified Manager Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)