Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23437

Опубликовано: 24 янв. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

A flaw was found in the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This issue causes the XercesJ XML parser to wait in an infinite loop, which may consume system resources for a prolonged duration, leading to a denial of service condition.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xerces-j2Out of support scope
Red Hat Enterprise Linux 7xerces-j2Out of support scope
Red Hat Enterprise Linux 8pki-deps:10.6/xerces-j2Will not fix
Red Hat Enterprise Linux 9xerces-j2Will not fix
Red Hat JBoss Enterprise Application Platform 6xerces-j2-eap6Out of support scope
Red Hat JBoss Web Server 3xerces-j2Not affected
Red Hat Software Collectionsrh-maven36-xerces-j2Will not fix
Red Hat JBoss Enterprise Application Platform 7xerces-j2FixedRHSA-2022:492206.06.2022
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-xerces-j2FixedRHSA-2022:491906.06.2022
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7eap7-xerces-j2FixedRHSA-2022:491806.06.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2047200xerces-j2: infinite loop when handling specially crafted XML document payloads

EPSS

Процентиль: 91%
0.0444
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CVSS3: 6.5
nvd
больше 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CVSS3: 6.5
debian
больше 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML pa ...

suse-cvrf
больше 4 лет назад

Security update for xerces-j2

suse-cvrf
больше 4 лет назад

Security update for xerces-j2

EPSS

Процентиль: 91%
0.0444
Низкий

6.5 Medium

CVSS3