There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
References
Link | Resource |
---|---|
https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl | Mailing List Vendor Advisory |
http://www.openwall.com/lists/oss-security/2022/01/24/3 | Mailing List Third Party Advisory |
https://www.oracle.com/security-alerts/cpuapr2022.html | Patch Third Party Advisory |
https://www.oracle.com/security-alerts/cpujul2022.html | Patch Third Party Advisory |
https://security.netapp.com/advisory/ntap-20221028-0005/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
07 Dec 2022, 01:45
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_party_management:2.7.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* cpe:2.3:a:oracle:health_sciences_information_manager:3.0.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_asap:7.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:* cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:13.9.4.2.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:health_sciences_information_manager:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:flexcube_universal_banking:12.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:oracle:banking_deposits_and_lines_of_credit_servicing:2.7:*:*:*:*:*:*:* |
|
First Time |
Oracle primavera Gateway
Oracle banking Deposits And Lines Of Credit Servicing Netapp active Iq Unified Manager Oracle agile Plm Netapp Oracle global Lifecycle Management Opatch Oracle peoplesoft Enterprise Peopletools Oracle product Lifecycle Analytics Oracle communications Asap Oracle financial Services Crime And Compliance Management Studio Oracle agile Engineering Data Management Oracle flexcube Universal Banking Oracle health Sciences Information Manager Oracle global Lifecycle Management Nextgen Oui Framework Oracle banking Party Management |
|
References | (CONFIRM) https://security.netapp.com/advisory/ntap-20221028-0005/ - Third Party Advisory | |
References | (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - Patch, Third Party Advisory |
28 Oct 2022, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
25 Jul 2022, 18:21
Type | Values Removed | Values Added |
---|---|---|
References |
|
16 Jun 2022, 21:21
Type | Values Removed | Values Added |
---|---|---|
First Time |
Oracle retail Service Backbone
Oracle communications Element Manager Oracle retail Financial Integration Oracle retail Integration Bus Oracle communications Session Route Manager Oracle communications Session Report Manager Oracle financial Services Behavior Detection Platform Oracle retail Bulk Data Integration Oracle ilearning Oracle retail Extract Transform And Load Oracle retail Merchandising System Oracle financial Services Enterprise Case Management Oracle Oracle weblogic Server Oracle financial Services Analytical Applications Infrastructure |
|
References | (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory | |
CPE | cpe:2.3:a:oracle:retail_financial_integration:14.1.3.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:ilearning:6.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.7.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_service_backbone:16.0.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_service_backbone:19.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_integration_bus:15.0.3.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_extract_transform_and_load:13.2.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_merchandising_system:16.0.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:ilearning:6.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_behavior_detection_platform:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.8.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_service_backbone:14.1.3.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_financial_integration:16.0.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_financial_integration:15.0.3.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_integration_bus:19.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_financial_integration:19.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_service_backbone:15.0.3.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_merchandising_system:19.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.8.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.7.1:*:*:*:*:*:*:* |
20 Apr 2022, 00:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Feb 2022, 17:23
Type | Values Removed | Values Added |
---|---|---|
References | (CONFIRM) https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl - Mailing List, Vendor Advisory | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2022/01/24/3 - Mailing List, Third Party Advisory | |
CWE | CWE-91 | |
CPE | cpe:2.3:a:apache:xerces-j:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 7.1
v3 : 6.5 |
First Time |
Apache xerces-j
Apache |
24 Jan 2022, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-01-24 15:15
Updated : 2022-12-07 01:45
NVD link : CVE-2022-23437
Mitre link : CVE-2022-23437
JSON object : View
Products Affected
apache
- xerces-j
oracle
- retail_bulk_data_integration
- ilearning
- communications_session_report_manager
- retail_integration_bus
- weblogic_server
- financial_services_behavior_detection_platform
- financial_services_enterprise_case_management
- retail_financial_integration
- primavera_gateway
- product_lifecycle_analytics
- agile_engineering_data_management
- communications_asap
- financial_services_analytical_applications_infrastructure
- peoplesoft_enterprise_peopletools
- agile_plm
- flexcube_universal_banking
- communications_session_route_manager
- communications_element_manager
- banking_deposits_and_lines_of_credit_servicing
- global_lifecycle_management_nextgen_oui_framework
- financial_services_crime_and_compliance_management_studio
- retail_service_backbone
- retail_extract_transform_and_load
- health_sciences_information_manager
- global_lifecycle_management_opatch
- retail_merchandising_system
- banking_party_management
netapp
- active_iq_unified_manager
CWE
CWE-91
XML Injection (aka Blind XPath Injection)