← Browse

CVE-2022-23437

Medium

Elevated severity or exploit probability.

CVSS base
6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS — probability of exploitation (30 days)
11.6%
95.8th percentile
CISA KEV
Not listed
Weakness / dates
CWE-835
Published 2022-01-24 · modified 2026-08-25

Description

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

Affected

apache netapp oracle

References

Official: NVD · CVE.org