Infinite loop within Apache XercesJ xml parser
Summary
| CVE | CVE-2022-23437 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-24 15:15:09 UTC |
| Updated | 2026-08-25 16:28:27 UTC |
| Description | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS: 0.116150000 probability, percentile 0.957080000 (date 2026-08-25)
Problem Types: CWE-835 | Infinite loop within Apache XercesJ xml parser
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 7.1 | AV:N/AC:M/Au:N/C:N/I:N/A:C |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:M/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Xerces | affected Apache XercesJ 2.12.1 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Critical Patch Update Advisory - April 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| CVE-2022-23437 Apache XercesJ Vulnerability in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Vendor Advisory |
| Oracle Critical Patch Update Advisory - July 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| oss-security - CVE-2022-23437: Infinite loop within Apache XercesJ xml parser | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: This issue was discovered by Sergey Temnikov and Ziyi Luo, from Amazon Corretto/JDK Team (en)
Additional Advisory Data
Workarounds
CNA: Apache XercesJ users, should migrate to version 2.12.2
Legacy QID Mappings
- 150538 Oracle WebLogic Server Multiple Vulnerabilities (CPUAPR2022)
- 150588 Oracle WebLogic Server Multiple Vulnerabilities (CPUOCT2022)
- 240458 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 7 (RHSA-2022:4918)
- 240459 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 8 (RHSA-2022:4919)
- 671576 EulerOS Security Update for xerces-j2 (EulerOS-SA-2022-1555)
- 671600 EulerOS Security Update for xerces-j2 (EulerOS-SA-2022-1592)
- 671719 EulerOS Security Update for xerces-j2 (EulerOS-SA-2022-1772)
- 751728 SUSE Enterprise Linux Security Update for xerces-j2 (SUSE-SU-2022:0500-1)
- 751729 SUSE Enterprise Linux Security Update for xerces-j2 (SUSE-SU-2022:0503-1)
- 751734 SUSE Enterprise Linux Security Update for xerces-j2 (SUSE-SU-2022:0542-1)
- 751745 OpenSUSE Security Update for xerces-j2 (openSUSE-SU-2022:0503-1)
- 751746 OpenSUSE Security Update for xerces-j2 (openSUSE-SU-2022:0500-1)
- 753451 SUSE Enterprise Linux Security Update for xerces-j2 (SUSE-SU-2022:14889-1)
- 87489 Oracle WebLogic Server Multiple Vulnerabilities (CPUAPR2022)
- 87524 Oracle WebLogic Server Multiple Vulnerabilities (CPUOCT2022)