CVE-2022-23437

MEDIUMCVSS 6.5/10EPSS 4.44%

Last modified

CVE-2022-23437 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. EPSS estimates a 4.44% chance of exploitation in the next 30 days.

Description

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Probability
4.44%

90.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ApacheXerces-J<= 2.12.1
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Plm9.3.6
OracleBanking Deposits And Lines Of Credit Servicing2.7
OracleBanking Party Management2.7.0
OracleCommunications Asap7.3
OracleCommunications Element Manager< 9.0
OracleCommunications Session Report Manager< 9.0
OracleCommunications Session Route Manager< 9.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6.0.0, <= 8.0.9.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.1.0.0, < 8.1.2.0
OracleFinancial Services Behavior Detection Platform>= 8.0.6.0.0, <= 8.0.8.0
OracleFinancial Services Behavior Detection Platform8.1.1.0
OracleFinancial Services Behavior Detection Platform8.1.1.1
OracleFinancial Services Behavior Detection Platform8.1.2.0
OracleFinancial Services Crime And Compliance Management Studio8.0.8.2.0
OracleFinancial Services Crime And Compliance Management Studio8.0.8.3.0
OracleFinancial Services Enterprise Case Management8.0.7.1
OracleFinancial Services Enterprise Case Management8.0.7.2.0
OracleFinancial Services Enterprise Case Management8.0.8.0
OracleFinancial Services Enterprise Case Management8.0.8.1
OracleFinancial Services Enterprise Case Management8.1.1.0
OracleFinancial Services Enterprise Case Management8.1.1.1
OracleFlexcube Universal Banking12.4.0
OracleGlobal Lifecycle Management Nextgen Oui Framework< 13.9.4.2.2
OracleGlobal Lifecycle Management Nextgen Oui Framework13.9.4.2.2
OracleGlobal Lifecycle Management Opatch< 12.2.0.1.30
OracleHealth Sciences Information Manager>= 3.0.1, <= 3.0.5
OracleHealth Sciences Information Manager3.0.0.1
OracleIlearning6.2
OracleIlearning6.3
OraclePeoplesoft Enterprise Peopletools8.58
OraclePeoplesoft Enterprise Peopletools8.59
OraclePrimavera Gateway>= 17.7, <= 17.12.11
OraclePrimavera Gateway>= 18.8.0, <= 18.8.14
OraclePrimavera Gateway>= 19.12.0, <= 19.12.13
OraclePrimavera Gateway>= 20.12.0, <= 20.12.8
OracleProduct Lifecycle Analytics3.6.1
OracleRetail Bulk Data Integration16.0.3.0
OracleRetail Extract Transform And Load13.2.8
OracleRetail Financial Integration14.1.3.2
OracleRetail Financial Integration15.0.3.1
OracleRetail Financial Integration16.0.3
OracleRetail Financial Integration19.0.1
OracleRetail Integration Bus14.1.3.2
OracleRetail Integration Bus15.0.3.1
OracleRetail Integration Bus16.0.3
OracleRetail Integration Bus19.0.1
OracleRetail Merchandising System16.0.3
OracleRetail Merchandising System19.0.1

Showing 50 of 58 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-23437?
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
How severe is CVE-2022-23437?
CVE-2022-23437 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 4.44% probability of exploitation in the next 30 days.
How do I fix CVE-2022-23437?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-23437?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST