7.1

CVE-2022-23437

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheXerces-j Version <= 2.12.1
OracleAgile Plm Version9.3.6
OracleBanking Party Management Version2.7.0
OracleCommunications Asap Version7.3
OracleFinancial Services Behavior Detection Platform Version >= 8.0.6.0.0 <= 8.0.8.0
OracleGlobal Lifecycle Management Opatch Version < 12.2.0.1.30
OracleHealth Sciences Information Manager Version >= 3.0.1 <= 3.0.5
OracleIlearning Version6.2
OracleIlearning Version6.3
OraclePrimavera Gateway Version >= 17.7 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.14
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.13
OraclePrimavera Gateway Version >= 20.12.0 <= 20.12.8
OracleRetail Bulk Data Integration Version16.0.3.0
OracleRetail Financial Integration Version14.1.3.2
OracleRetail Financial Integration Version15.0.3.1
OracleRetail Integration Bus Version14.1.3.2
OracleRetail Integration Bus Version15.0.3.1
OracleRetail Integration Bus Version16.0.3
OracleRetail Integration Bus Version19.0.1
OracleRetail Service Backbone Version14.1.3.2
OracleRetail Service Backbone Version15.0.3.1
OracleRetail Service Backbone Version16.0.3
OracleRetail Service Backbone Version19.0.1
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
NetappActive Iq Unified Manager Version- SwPlatformwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.265
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvd@nist.gov 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.