CVE-2022-34169
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
Published:Jul 19, 2022
Last Modified:May 20, 2025
EPS:Jul 19, 2022
EPSS Score:0.10953
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Xalan-java
Apache
Xalan-java
Vendor
Azul
Product
Zulu
Azul
Zulu
Vendor
Debian
Product
Debian Linux
Debian
Debian Linux
Vendor
Fedoraproject
Product
Fedora
Fedoraproject
Fedora
Vendor
Netapp
Product
7-mode Transition Tool
Netapp
7-mode Transition Tool
Vendor
Netapp
Product
Active Iq Unified Manager
Netapp
Active Iq Unified Manager
Vendor
Netapp
Product
Cloud Insights Acquisition Unit
Netapp
Cloud Insights Acquisition Unit
Vendor
Netapp
Product
Cloud Secure Agent
Netapp
Cloud Secure Agent
Vendor
Netapp
Product
Hci Compute Node
Netapp
Hci Compute Node
Vendor
Netapp
Product
Hci Management Node
Netapp
Hci Management Node
Vendor
Netapp
Product
Oncommand Insight
Netapp
Oncommand Insight
Vendor
Netapp
Product
Solidfire
Netapp
Solidfire
Vendor
Oracle
Product
Graalvm
Oracle
Graalvm
Vendor
Oracle
Product
Jdk
Oracle
Jdk
Vendor
Oracle
Product
Jre
Oracle
Jre
Vendor
Oracle
Product
Openjdk
Oracle
Openjdk
Vendor
Redhat
Product
Apache Camel Spring Boot
Redhat
Apache Camel Spring Boot
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Jboss Enterprise Application Platform
Redhat
Jboss Enterprise Application Platform
Vendor
Redhat
Product
Jboss Enterprise Application Platform Eus
Redhat
Jboss Enterprise Application Platform Eus
Vendor
Redhat
Product
Openjdk
Redhat
Openjdk
Vendor
Redhat
Product
Rhel E4s
Redhat
Rhel E4s
Vendor
Redhat
Product
Rhel Eus
Redhat
Rhel Eus
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
