Vulnerability record · CVE-2022-23437 · published 24 January 2022
CVE-2022-23437: Apache xerces-j vulnerability
Apache · Xerces J
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
Description
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected products
29 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2022/01/24/3 | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl | Mailing ListVendor Advisory |
| https://security.netapp.com/advisory/ntap-20221028-0005/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html | PatchThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2022/01/24/3 | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl | Mailing ListVendor Advisory |
| https://security.netapp.com/advisory/ntap-20221028-0005/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html | PatchThird Party Advisory |
Track CVE-2022-23437 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23437), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.