CVE-2022-23437

medium Apache
CVSS v3 Base Score
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
11.6%
Exploitation probability in 30 days
Top 4% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
None
Integrity
None
Availability
High
Published: January 24, 2022 (1687 days ago)
Last Modified: August 25, 2026
Vendor: Apache
Source: NVD

Description

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CWE

CWE-835

Affected Products

apache xerces-joracle agile engineering data managementoracle agile product lifecycle managementoracle banking deposits and lines of credit servicingoracle banking party managementoracle communications asaporacle communications element manageroracle communications session report manageroracle communications session route manageroracle financial services analytical applications infrastructure

References