CVE-2022-23437 is a denial-of-service vulnerability in Apache Xerces Java (XercesJ) XML parser, affecting versions 2.12.1 and earlier, as well as products from Apache, NetApp, and Oracle that utilize it. An unauthenticated attacker can trigger an infinite loop by submitting a specially crafted XML document, leading to high availability impact and resource exhaustion. While the CVSS score is 6.5 (Medium), there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.12.1CPE matchmatch criteria | cpe:2.3:a:apache:xerces-j:*:*:*:*:*:*:*:* | ||
6.2.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:* | ||
9.3.6CPE matchmatch criteria | cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:* | ||
2.7CPE matchmatch criteria | cpe:2.3:a:oracle:banking_deposits_and_lines_of_credit_servicing:2.7:*:*:*:*:*:*:* | ||
2.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:banking_party_management:2.7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.