Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23437

Опубликовано: 24 янв. 2022
Источник: redhat
CVSS3: 6.5

Описание

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

A flaw was found in the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This issue causes the XercesJ XML parser to wait in an infinite loop, which may consume system resources for a prolonged duration, leading to a denial of service condition.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xerces-j2Out of support scope
Red Hat Enterprise Linux 7xerces-j2Out of support scope
Red Hat Enterprise Linux 8pki-deps:10.6/xerces-j2Will not fix
Red Hat Enterprise Linux 9xerces-j2Will not fix
Red Hat JBoss Enterprise Application Platform 6xerces-j2-eap6Out of support scope
Red Hat JBoss Web Server 3xerces-j2Not affected
Red Hat Software Collectionsrh-maven36-xerces-j2Will not fix
Moderate: Red Hat JBoss Enterprise Application Platform 7.4.5 security updatexerces-j2FixedRHSA-2022:492206.06.2022
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-xerces-j2FixedRHSA-2022:491906.06.2022
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7eap7-xerces-j2FixedRHSA-2022:491806.06.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2047200xerces-j2: infinite loop when handling specially crafted XML document payloads

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CVSS3: 6.5
nvd
около 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CVSS3: 6.5
debian
около 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML pa ...

suse-cvrf
почти 4 года назад

Security update for xerces-j2

suse-cvrf
почти 4 года назад

Security update for xerces-j2

6.5 Medium

CVSS3