There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

Project Subscriptions

Vendors Products
Xerces-j Subscribe
Active Iq Unified Manager Subscribe
Agile Engineering Data Management Subscribe
Agile Plm Subscribe
Banking Deposits And Lines Of Credit Servicing Subscribe
Banking Party Management Subscribe
Communications Asap Subscribe
Communications Element Manager Subscribe
Communications Session Report Manager Subscribe
Communications Session Route Manager Subscribe
Financial Services Analytical Applications Infrastructure Subscribe
Financial Services Behavior Detection Platform Subscribe
Financial Services Crime And Compliance Management Studio Subscribe
Financial Services Enterprise Case Management Subscribe
Flexcube Universal Banking Subscribe
Global Lifecycle Management Nextgen Oui Framework Subscribe
Global Lifecycle Management Opatch Subscribe
Health Sciences Information Manager Subscribe
Ilearning Subscribe
Peoplesoft Enterprise Peopletools Subscribe
Primavera Gateway Subscribe
Product Lifecycle Analytics Subscribe
Retail Bulk Data Integration Subscribe
Retail Extract Transform And Load Subscribe
Retail Financial Integration Subscribe
Retail Integration Bus Subscribe
Retail Merchandising System Subscribe
Retail Service Backbone Subscribe
Weblogic Server Subscribe
Jboss Enterprise Application Platform Subscribe
Jboss Enterprise Bpms Platform Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-0613 There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
Github GHSA Github GHSA GHSA-h65f-jvqw-m9fj Infinite Loop in Apache Xerces Java
Fixes

Solution

No solution given by the vendor.


Workaround

Apache XercesJ users, should migrate to version 2.12.2

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T03:43:45.690Z

Reserved: 2022-01-19T00:00:00

Link: CVE-2022-23437

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-24T15:15:09.317

Modified: 2024-11-21T06:48:33.283

Link: CVE-2022-23437

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-01-24T00:00:00Z

Links: CVE-2022-23437 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses