MEDIUM · 6.5

CVE-2022-23437

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which...

Vulnerability Description

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ApacheXerces-J<= 2.12.1
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Plm9.3.6
OracleBanking Deposits And Lines Of Credit Servicing2.7
OracleBanking Party Management2.7.0
OracleCommunications Asap7.3
OracleCommunications Element Manager< 9.0
OracleCommunications Session Report Manager< 9.0
OracleCommunications Session Route Manager< 9.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6.0.0, <= 8.0.9.0
OracleFinancial Services Behavior Detection Platform>= 8.0.6.0.0, <= 8.0.8.0
OracleFinancial Services Crime And Compliance Management Studio8.0.8.2.0
OracleFinancial Services Enterprise Case Management8.0.7.1
OracleFlexcube Universal Banking12.4.0
OracleGlobal Lifecycle Management Nextgen Oui Framework< 13.9.4.2.2
OracleGlobal Lifecycle Management Opatch< 12.2.0.1.30
OracleHealth Sciences Information Manager>= 3.0.1, <= 3.0.5
OracleIlearning6.2
OraclePeoplesoft Enterprise Peopletools8.58
OraclePrimavera Gateway>= 17.7, <= 17.12.11

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-23437?

CVE-2022-23437 is a vulnerability with a CVSS score of 6.5 (MEDIUM). There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which...

How severe is CVE-2022-23437?

CVE-2022-23437 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-23437?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Xerces-J, Oracle Agile Engineering Data Management, Oracle Agile Plm, Oracle Banking Deposits And Lines Of Credit Servicing, Oracle Banking Party Management.