7.1
CVE-2022-23437
- EPSS 4.44%
- Veröffentlicht 24.01.2022 15:15:09
- Zuletzt bearbeitet 25.08.2026 16:28:27
- Erkennungen
Infinite loop within Apache XercesJ xml parser
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Agile Engineering Data Management Version 6.2.1.0
Oracle ≫ Agile Product Lifecycle Management Version 9.3.6
Oracle ≫ Banking Deposits And Lines Of Credit Servicing Version 2.7
Oracle ≫ Banking Party Management Version 2.7.0
Oracle ≫ Communications Asap Version 7.3
Oracle ≫ Communications Element Manager Version < 9.0
Oracle ≫ Communications Session Report Manager Version < 9.0
Oracle ≫ Communications Session Route Manager Version < 9.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.6.0.0 <= 8.0.9.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.1.0.0 < 8.1.2.0
Oracle ≫ Financial Services Behavior Detection Platform Version >= 8.0.6.0.0 <= 8.0.8.0
Oracle ≫ Financial Services Behavior Detection Platform Version 8.1.1.0
Oracle ≫ Financial Services Behavior Detection Platform Version 8.1.1.1
Oracle ≫ Financial Services Behavior Detection Platform Version 8.1.2.0
Oracle ≫ Financial Services Crime And Compliance Management Studio Version 8.0.8.2.0
Oracle ≫ Financial Services Crime And Compliance Management Studio Version 8.0.8.3.0
Oracle ≫ Financial Services Enterprise Case Management Version 8.0.7.1
Oracle ≫ Financial Services Enterprise Case Management Version 8.0.7.2.0
Oracle ≫ Financial Services Enterprise Case Management Version 8.0.8.0
Oracle ≫ Financial Services Enterprise Case Management Version 8.0.8.1
Oracle ≫ Financial Services Enterprise Case Management Version 8.1.1.0
Oracle ≫ Financial Services Enterprise Case Management Version 8.1.1.1
Oracle ≫ Flexcube Universal Banking Version 12.4.0
Oracle ≫ Global Lifecycle Management Nextgen Oui Framework Version < 13.9.4.2.2
Oracle ≫ Global Lifecycle Management Nextgen Oui Framework Version 13.9.4.2.2
Oracle ≫ Global Lifecycle Management Opatch Version < 12.2.0.1.30
Oracle ≫ Health Sciences Information Manager Version >= 3.0.1 <= 3.0.5
Oracle ≫ Health Sciences Information Manager Version 3.0.0.1
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.58
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.59
Oracle ≫ Primavera Gateway Version >= 17.7 <= 17.12.11
Oracle ≫ Primavera Gateway Version >= 18.8.0 <= 18.8.14
Oracle ≫ Primavera Gateway Version >= 19.12.0 <= 19.12.13
Oracle ≫ Primavera Gateway Version >= 20.12.0 <= 20.12.8
Oracle ≫ Product Lifecycle Analytics Version 3.6.1
Oracle ≫ Retail Bulk Data Integration Version 16.0.3.0
Oracle ≫ Retail Extract Transform And Load Version 13.2.8
Oracle ≫ Retail Financial Integration Version 14.1.3.2
Oracle ≫ Retail Financial Integration Version 15.0.3.1
Oracle ≫ Retail Financial Integration Version 16.0.3
Oracle ≫ Retail Financial Integration Version 19.0.1
Oracle ≫ Retail Integration Bus Version 14.1.3.2
Oracle ≫ Retail Integration Bus Version 15.0.3.1
Oracle ≫ Retail Integration Bus Version 16.0.3
Oracle ≫ Retail Integration Bus Version 19.0.1
Oracle ≫ Retail Merchandising System Version 16.0.3
Oracle ≫ Retail Merchandising System Version 19.0.1
Oracle ≫ Retail Service Backbone Version 14.1.3.2
Oracle ≫ Retail Service Backbone Version 15.0.3.1
Oracle ≫ Retail Service Backbone Version 16.0.3
Oracle ≫ Retail Service Backbone Version 19.0.1
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Oracle ≫ Weblogic Server Version 14.1.1.0.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.44% | 0.902 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| NIST | 7.1 | 8.6 | 6.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:C
|
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
http://www.openwall.com/lists/oss-security/2022/01/24/3
https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl
https://security.netapp.com/advisory/ntap-20221028-0005/