CVE-2022-34169
Last modified
CVE-2022-34169 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. EPSS estimates a 17.67% chance of exploitation in the next 30 days.
Description
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apache | Xalan-Java | <= 2.7.2 | — |
| Debian | Debian Linux | 10.0 | — |
| Debian | Debian Linux | 11.0 | — |
| Oracle | Graalvm | 20.3.6 | — |
| Oracle | Graalvm | 21.3.2 | — |
| Oracle | Graalvm | 22.1.0 | — |
| Oracle | Jdk | 1.7.0 | Update343 |
| Oracle | Jdk | 1.8.0 | Update333 |
| Oracle | Jdk | 11.0.15.1 | — |
| Oracle | Jdk | 17.0.3.1 | — |
| Oracle | Jdk | 18.0.1.1 | — |
| Oracle | Jre | 1.7.0 | Update343 |
| Oracle | Jre | 1.8.0 | Update333 |
| Oracle | Jre | 11.0.15.1 | — |
| Oracle | Jre | 17.0.3.1 | — |
| Oracle | Jre | 18.0.1.1 | — |
| Oracle | Openjdk | >= 11, <= 11.0.15 | — |
| Oracle | Openjdk | >= 13, <= 13.0.11 | — |
| Oracle | Openjdk | >= 15, <= 15.0.7 | — |
| Oracle | Openjdk | >= 17, <= 17.0.3 | — |
| Oracle | Openjdk | 7 | — |
| Oracle | Openjdk | 8 | — |
| Oracle | Openjdk | 18 | — |
| Fedoraproject | Fedora | 35 | — |
| Fedoraproject | Fedora | 36 | — |
| Netapp | 7-Mode Transition Tool | All versions | — |
| Netapp | Active Iq Unified Manager | All versions | — |
| Netapp | Cloud Insights Acquisition Unit | All versions | — |
| Netapp | Cloud Secure Agent | All versions | — |
| Netapp | Hci Management Node | All versions | — |
| Netapp | Oncommand Insight | All versions | — |
| Netapp | Solidfire | All versions | — |
| Netapp | Hci Compute Node | All versions | — |
| Azul | Zulu | 6.47 | — |
| Azul | Zulu | 7.54 | — |
| Azul | Zulu | 8.62 | — |
| Azul | Zulu | 11.56 | — |
| Azul | Zulu | 13.48 | — |
| Azul | Zulu | 15.40 | — |
| Azul | Zulu | 17.34 | — |
| Azul | Zulu | 18.30 | — |
References
- http://packetstormsecurity.com/files/168186/Xalan-J-XSLTC-Integer-Truncation.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2022/07/19/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/07/19/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/07/20/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/07/20/3Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/10/18/2Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/04/8Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/07/2Mailing List, Third Party Advisory
- https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kywIssue Tracking, Mailing List, Vendor Advisory
- https://lists.apache.org/thread/2qvl7r43wb4t8p9dd9om1bnkssk07sn8Issue Tracking, Mailing List, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00024.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220729-0009/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5188Third Party Advisory
- https://www.debian.org/security/2022/dsa-5192Third Party Advisory
- https://www.debian.org/security/2022/dsa-5256Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- http://packetstormsecurity.com/files/168186/Xalan-J-XSLTC-Integer-Truncation.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2022/07/19/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/07/19/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/07/20/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/07/20/3Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/10/18/2Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/04/8Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/07/2Mailing List, Third Party Advisory
- https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kywIssue Tracking, Mailing List, Vendor Advisory
- https://lists.apache.org/thread/2qvl7r43wb4t8p9dd9om1bnkssk07sn8Issue Tracking, Mailing List, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00024.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220729-0009/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5188Third Party Advisory
- https://www.debian.org/security/2022/dsa-5192Third Party Advisory
- https://www.debian.org/security/2022/dsa-5256Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-34169?
How severe is CVE-2022-34169?
How do I fix CVE-2022-34169?
Are you affected by CVE-2022-34169?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
