CVE-2022-23437: Infinite loop within Apache XercesJ xml parser
A flaw was found in the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This issue causes the XercesJ XML parser to wait in an infinite loop, which may consume system resources for a prolonged duration, leading to a denial of service condition.
Other sources
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-23437?
CVE-2022-23437 is classified as a denial of service vulnerability.
How do I fix CVE-2022-23437?
To mitigate CVE-2022-23437, update Apache Xerces-J to versions 2.12.2 or higher, or apply the relevant patches from your software vendor.
Which Apache Xerces-J versions are affected by CVE-2022-23437?
CVE-2022-23437 affects Apache Xerces-J up to version 2.12.1.
Can CVE-2022-23437 be exploited remotely?
Yes, CVE-2022-23437 can be exploited remotely by convincing a user to open a specially-crafted XML document.
What types of applications are susceptible to CVE-2022-23437?
Applications using vulnerable versions of Apache Xerces-J, including various Oracle and IBM products, are susceptible to CVE-2022-23437.