CVE-2022-23437
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
Published:Jan 24, 2022
Last Modified:Aug 25, 2026
EPS:Jan 24, 2022
EPSS Score:0.11615
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Xerces-j
Apache
Xerces-j
Vendor
Netapp
Product
Active Iq Unified Manager
Netapp
Active Iq Unified Manager
Vendor
Oracle
Product
Agile Engineering Data Management
Oracle
Agile Engineering Data Management
Vendor
Oracle
Product
Agile Product Lifecycle Management
Oracle
Agile Product Lifecycle Management
Vendor
Oracle
Product
Banking Deposits And Lines Of Credit Servicing
Oracle
Banking Deposits And Lines Of Credit Servicing
Vendor
Oracle
Product
Banking Party Management
Oracle
Banking Party Management
Vendor
Oracle
Product
Communications Asap
Oracle
Communications Asap
Vendor
Oracle
Product
Communications Element Manager
Oracle
Communications Element Manager
Vendor
Oracle
Product
Communications Session Report Manager
Oracle
Communications Session Report Manager
Vendor
Oracle
Product
Communications Session Route Manager
Oracle
Communications Session Route Manager
Vendor
Oracle
Product
Financial Services Analytical Applications Infrastructure
Oracle
Financial Services Analytical Applications Infrastructure
Vendor
Oracle
Product
Financial Services Behavior Detection Platform
Oracle
Financial Services Behavior Detection Platform
Vendor
Oracle
Product
Financial Services Crime And Compliance Management Studio
Oracle
Financial Services Crime And Compliance Management Studio
Vendor
Oracle
Product
Financial Services Enterprise Case Management
Oracle
Financial Services Enterprise Case Management
Vendor
Oracle
Product
Flexcube Universal Banking
Oracle
Flexcube Universal Banking
Vendor
Oracle
Product
Global Lifecycle Management Nextgen Oui Framework
Oracle
Global Lifecycle Management Nextgen Oui Framework
Vendor
Oracle
Product
Global Lifecycle Management Opatch
Oracle
Global Lifecycle Management Opatch
Vendor
Oracle
Product
Health Sciences Information Manager
Oracle
Health Sciences Information Manager
Vendor
Oracle
Product
Ilearning
Oracle
Ilearning
Vendor
Oracle
Product
Peoplesoft Enterprise Peopletools
Oracle
Peoplesoft Enterprise Peopletools
Vendor
Oracle
Product
Primavera Gateway
Oracle
Primavera Gateway
Vendor
Oracle
Product
Product Lifecycle Analytics
Oracle
Product Lifecycle Analytics
Vendor
Oracle
Product
Retail Bulk Data Integration
Oracle
Retail Bulk Data Integration
Vendor
Oracle
Product
Retail Extract Transform And Load
Oracle
Retail Extract Transform And Load
Vendor
Oracle
Product
Retail Financial Integration
Oracle
Retail Financial Integration
Vendor
Oracle
Product
Retail Integration Bus
Oracle
Retail Integration Bus
Vendor
Oracle
Product
Retail Merchandising System
Oracle
Retail Merchandising System
Vendor
Oracle
Product
Retail Service Backbone
Oracle
Retail Service Backbone
Vendor
Oracle
Product
Weblogic Server
Oracle
Weblogic Server
Vendor
Redhat
Product
Jboss Enterprise Application Platform
Redhat
Jboss Enterprise Application Platform
Vendor
Redhat
Product
Jboss Enterprise Bpms Platform
Redhat
Jboss Enterprise Bpms Platform
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
