CVE Feed

    Dashboard / CVE / CVE-2022-23437

    CVE-2022-23437

    There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

    Published:Jan 24, 2022
    Last Modified:Aug 25, 2026
    EPS:Jan 24, 2022
    EPSS Score:0.11615
    CVSS Score:6.5

    Affected Products

    Vendor
    Apache
    Product
    Xerces-j
    Vendor
    Netapp
    Product
    Active Iq Unified Manager
    Vendor
    Oracle
    Product
    Agile Engineering Data Management
    Vendor
    Oracle
    Product
    Agile Product Lifecycle Management
    Vendor
    Oracle
    Product
    Banking Deposits And Lines Of Credit Servicing
    Vendor
    Oracle
    Product
    Banking Party Management
    Vendor
    Oracle
    Product
    Communications Asap
    Vendor
    Oracle
    Product
    Communications Element Manager
    Vendor
    Oracle
    Product
    Communications Session Report Manager
    Vendor
    Oracle
    Product
    Communications Session Route Manager
    Vendor
    Oracle
    Product
    Financial Services Analytical Applications Infrastructure
    Vendor
    Oracle
    Product
    Financial Services Behavior Detection Platform
    Vendor
    Oracle
    Product
    Financial Services Crime And Compliance Management Studio
    Vendor
    Oracle
    Product
    Financial Services Enterprise Case Management
    Vendor
    Oracle
    Product
    Flexcube Universal Banking
    Vendor
    Oracle
    Product
    Global Lifecycle Management Nextgen Oui Framework
    Vendor
    Oracle
    Product
    Global Lifecycle Management Opatch
    Vendor
    Oracle
    Product
    Health Sciences Information Manager
    Vendor
    Oracle
    Product
    Ilearning
    Vendor
    Oracle
    Product
    Peoplesoft Enterprise Peopletools
    Vendor
    Oracle
    Product
    Primavera Gateway
    Vendor
    Oracle
    Product
    Product Lifecycle Analytics
    Vendor
    Oracle
    Product
    Retail Bulk Data Integration
    Vendor
    Oracle
    Product
    Retail Extract Transform And Load
    Vendor
    Oracle
    Product
    Retail Financial Integration
    Vendor
    Oracle
    Product
    Retail Integration Bus
    Vendor
    Oracle
    Product
    Retail Merchandising System
    Vendor
    Oracle
    Product
    Retail Service Backbone
    Vendor
    Oracle
    Product
    Weblogic Server
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform
    Vendor
    Redhat
    Product
    Jboss Enterprise Bpms Platform

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High