CVE-2022-23437
Vulnerability Summary
Timeline
Description
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- v2.0•HIGH•Score: 7.1AV:N/AC:M/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 0.09%• Percentile: 25%
Techniques & Countermeasures
- CWE-835•Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Affected Systems
- apache software foundation•apache xerces
≥ Apache XercesJ, ≤ 2.12.1
- apache•xerces-j
≤ 2.12.1
- xerces•xercesImpl
< 2.12.2
- netapp•active_iq_unified_manager
na
- oracle•agile_engineering_data_management
6.2.1.0
- oracle•agile_plm
9.3.6
- oracle•banking_deposits_and_lines_of_credit_servicing
2.7
- oracle•banking_party_management
2.7.0
- oracle•communications_asap
7.3
- oracle•communications_element_manager
< 9.0
- oracle•communications_session_report_manager
< 9.0
- oracle•communications_session_route_manager
< 9.0
- oracle•financial_services_analytical_applications_infrastructure
≥ 8.0.6.0.0, ≤ 8.0.9.0 | ≥ 8.1.0.0, < 8.1.2.0
- oracle•financial_services_behavior_detection_platform
≥ 8.0.6.0.0, ≤ 8.0.8.0 | 8.1.1.0 | 8.1.1.1 | 8.1.2.0
- oracle•financial_services_crime_and_compliance_management_studio
8.0.8.2.0 | 8.0.8.3.0
- oracle•financial_services_enterprise_case_management
8.0.7.1 | 8.0.7.2.0 | 8.0.8.0 | 8.0.8.1 | 8.1.1.0 | 8.1.1.1
- oracle•flexcube_universal_banking
12.4.0
- oracle•global_lifecycle_management_nextgen_oui_framework
< 13.9.4.2.2 | 13.9.4.2.2
- oracle•global_lifecycle_management_opatch
< 12.2.0.1.30
- oracle•health_sciences_information_manager
≥ 3.0.1, ≤ 3.0.5 | 3.0.0.1
- oracle•ilearning
6.2 | 6.3
- oracle•peoplesoft_enterprise_peopletools
8.58 | 8.59
- oracle•primavera_gateway
≥ 17.7, ≤ 17.12.11 | ≥ 18.8.0, ≤ 18.8.14 | ≥ 19.12.0, ≤ 19.12.13 | ≥ 20.12.0, ≤ 20.12.8
- oracle•product_lifecycle_analytics
3.6.1
- oracle•retail_bulk_data_integration
16.0.3.0
- oracle•retail_extract_transform_and_load
13.2.8
- oracle•retail_financial_integration
14.1.3.2 | 15.0.3.1 | 16.0.3 | 19.0.1
- oracle•retail_integration_bus
14.1.3.2 | 15.0.3.1 | 16.0.3 | 19.0.1
- oracle•retail_merchandising_system
16.0.3 | 19.0.1
- oracle•retail_service_backbone
14.1.3.2 | 15.0.3.1 | 16.0.3 | 19.0.1
- Unknown•WebLogic Server
12.2.1.3.0 | 12.2.1.4.0 | 14.1.1.0.0
References (8)
- https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl
- http://www.openwall.com/lists/oss-security/2022/01/24/3
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://security.netapp.com/advisory/ntap-20221028-0005/
- https://nvd.nist.gov/vuln/detail/CVE-2022-23437
- https://github.com/jboss/xerces
- https://security.netapp.com/advisory/ntap-20221028-0005