CVE-2022-23437 (CNNVD-202201-2238)

MEDIUM
中文标题:
Xerces 安全漏洞
英文标题:
Infinite loop within Apache XercesJ xml parser
CVSS分数: 6.5
发布时间: 2022-01-24 00:00:00
漏洞类型: 其他
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v3
漏洞描述
中文描述:

Xerces是一个由Apache组织所推动的一项XML文档解析开源项目。 Apache Xerces Java (XercesJ) 2.12.1 和以前的版本中的 XML 解析器存在安全漏洞,攻击者可通过特制的 XML 文档负载导致 XercesJ XML 解析器在无限循环中等待,进而长时间消耗系统资源。

英文描述:

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CWE类型:
CWE-835
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
Apache Software Foundation Apache Xerces - ≤ 2.12.1 - cpe:2.3:a:apache_software_foundation:apache_xerces:*:*:*:*:*:*:*:*
apache xerces-j * - - cpe:2.3:a:apache:xerces-j:*:*:*:*:*:*:*:*
oracle agile_engineering_data_management 6.2.1.0 - - cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
oracle agile_plm 9.3.6 - - cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
oracle banking_deposits_and_lines_of_credit_servicing 2.7 - - cpe:2.3:a:oracle:banking_deposits_and_lines_of_credit_servicing:2.7:*:*:*:*:*:*:*
oracle banking_party_management 2.7.0 - - cpe:2.3:a:oracle:banking_party_management:2.7.0:*:*:*:*:*:*:*
oracle communications_asap 7.3 - - cpe:2.3:a:oracle:communications_asap:7.3:*:*:*:*:*:*:*
oracle communications_element_manager * - - cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:*
oracle communications_session_report_manager * - - cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*
oracle communications_session_route_manager * - - cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*
oracle financial_services_analytical_applications_infrastructure * - - cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*
oracle financial_services_behavior_detection_platform * - - cpe:2.3:a:oracle:financial_services_behavior_detection_platform:*:*:*:*:*:*:*:*
oracle financial_services_behavior_detection_platform 8.1.1.0 - - cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.0:*:*:*:*:*:*:*
oracle financial_services_behavior_detection_platform 8.1.1.1 - - cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.1:*:*:*:*:*:*:*
oracle financial_services_behavior_detection_platform 8.1.2.0 - - cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.0:*:*:*:*:*:*:*
oracle financial_services_crime_and_compliance_management_studio 8.0.8.2.0 - - cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*
oracle financial_services_crime_and_compliance_management_studio 8.0.8.3.0 - - cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*
oracle financial_services_enterprise_case_management 8.0.7.1 - - cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.7.1:*:*:*:*:*:*:*
oracle financial_services_enterprise_case_management 8.0.7.2.0 - - cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.7.2.0:*:*:*:*:*:*:*
oracle financial_services_enterprise_case_management 8.0.8.0 - - cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.8.0:*:*:*:*:*:*:*
oracle financial_services_enterprise_case_management 8.0.8.1 - - cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.8.1:*:*:*:*:*:*:*
oracle financial_services_enterprise_case_management 8.1.1.0 - - cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.0:*:*:*:*:*:*:*
oracle financial_services_enterprise_case_management 8.1.1.1 - - cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.1:*:*:*:*:*:*:*
oracle flexcube_universal_banking 12.4.0 - - cpe:2.3:a:oracle:flexcube_universal_banking:12.4.0:*:*:*:*:*:*:*
oracle global_lifecycle_management_nextgen_oui_framework * - - cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:*:*:*:*:*:*:*:*
oracle global_lifecycle_management_nextgen_oui_framework 13.9.4.2.2 - - cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:13.9.4.2.2:*:*:*:*:*:*:*
oracle global_lifecycle_management_opatch * - - cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:*
oracle health_sciences_information_manager * - - cpe:2.3:a:oracle:health_sciences_information_manager:*:*:*:*:*:*:*:*
oracle health_sciences_information_manager 3.0.0.1 - - cpe:2.3:a:oracle:health_sciences_information_manager:3.0.0.1:*:*:*:*:*:*:*
oracle ilearning 6.2 - - cpe:2.3:a:oracle:ilearning:6.2:*:*:*:*:*:*:*
oracle ilearning 6.3 - - cpe:2.3:a:oracle:ilearning:6.3:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_peopletools 8.58 - - cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_peopletools 8.59 - - cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*
oracle primavera_gateway * - - cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*
oracle product_lifecycle_analytics 3.6.1 - - cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
oracle retail_bulk_data_integration 16.0.3.0 - - cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3.0:*:*:*:*:*:*:*
oracle retail_extract_transform_and_load 13.2.8 - - cpe:2.3:a:oracle:retail_extract_transform_and_load:13.2.8:*:*:*:*:*:*:*
oracle retail_financial_integration 14.1.3.2 - - cpe:2.3:a:oracle:retail_financial_integration:14.1.3.2:*:*:*:*:*:*:*
oracle retail_financial_integration 15.0.3.1 - - cpe:2.3:a:oracle:retail_financial_integration:15.0.3.1:*:*:*:*:*:*:*
oracle retail_financial_integration 16.0.3 - - cpe:2.3:a:oracle:retail_financial_integration:16.0.3:*:*:*:*:*:*:*
oracle retail_financial_integration 19.0.1 - - cpe:2.3:a:oracle:retail_financial_integration:19.0.1:*:*:*:*:*:*:*
oracle retail_integration_bus 14.1.3.2 - - cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:*
oracle retail_integration_bus 15.0.3.1 - - cpe:2.3:a:oracle:retail_integration_bus:15.0.3.1:*:*:*:*:*:*:*
oracle retail_integration_bus 16.0.3 - - cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:*
oracle retail_integration_bus 19.0.1 - - cpe:2.3:a:oracle:retail_integration_bus:19.0.1:*:*:*:*:*:*:*
oracle retail_merchandising_system 16.0.3 - - cpe:2.3:a:oracle:retail_merchandising_system:16.0.3:*:*:*:*:*:*:*
oracle retail_merchandising_system 19.0.1 - - cpe:2.3:a:oracle:retail_merchandising_system:19.0.1:*:*:*:*:*:*:*
oracle retail_service_backbone 14.1.3.2 - - cpe:2.3:a:oracle:retail_service_backbone:14.1.3.2:*:*:*:*:*:*:*
oracle retail_service_backbone 15.0.3.1 - - cpe:2.3:a:oracle:retail_service_backbone:15.0.3.1:*:*:*:*:*:*:*
oracle retail_service_backbone 16.0.3 - - cpe:2.3:a:oracle:retail_service_backbone:16.0.3:*:*:*:*:*:*:*
oracle retail_service_backbone 19.0.1 - - cpe:2.3:a:oracle:retail_service_backbone:19.0.1:*:*:*:*:*:*:*
oracle weblogic_server 12.2.1.3.0 - - cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
oracle weblogic_server 12.2.1.4.0 - - cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
oracle weblogic_server 14.1.1.0.0 - - cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
netapp active_iq_unified_manager - - - cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
无标题 OTHER
cve.org
访问
[oss-security] 20220124 CVE-2022-23437: Infinite loop within Apache XercesJ xml parser mailing-list
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
CVSS评分详情
6.5
MEDIUM
CVSS向量: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS版本: 3.1
机密性
NONE
完整性
NONE
可用性
HIGH
时间信息
发布时间:
2022-01-24 00:00:00
修改时间:
2024-08-03 03:43:45
创建时间:
2025-11-11 15:37:20
更新时间:
2025-11-11 15:57:05
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2022-23437 2025-11-11 15:21:18 2025-11-11 07:37:20
NVD nvd_CVE-2022-23437 2025-11-11 14:58:14 2025-11-11 07:45:36
CNNVD cnnvd_CNNVD-202201-2238 2025-11-11 15:10:48 2025-11-11 07:57:05
版本与语言
当前版本: v3
主要语言: EN
支持语言:
EN ZH
安全公告
暂无安全公告信息
变更历史
v3 CNNVD
2025-11-11 15:57:05
vulnerability_type: 未提取 → 其他; cnnvd_id: 未提取 → CNNVD-202201-2238; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 其他
  • cnnvd_id: 未提取 -> CNNVD-202201-2238
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:45:36
cvss_score: 未提取 → 6.5; cvss_vector: NOT_EXTRACTED → CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H; cvss_version: NOT_EXTRACTED → 3.1; affected_products_count: 1 → 55; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • cvss_score: 未提取 -> 6.5
  • cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  • cvss_version: NOT_EXTRACTED -> 3.1
  • affected_products_count: 1 -> 55
  • data_sources: ['cve'] -> ['cve', 'nvd']