{"id":"CVE-2022-23437","title":"There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads","summary":"There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resourc…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-835"],"vendor":"apache","product":"xerces-j","affected":["xerces-j <= 2.12.1","agile_engineering_data_management = 6.2.1.0","agile_product_lifecycle_management = 9.3.6","banking_deposits_and_lines_of_credit_servicing = 2.7","banking_party_management = 2.7.0","communications_asap = 7.3","communications_element_manager < 9.0","communications_session_report_manager < 9.0","communications_session_route_manager < 9.0","financial_services_analytical_applications_infrastructure >= 8.0.6.0.0, <= 8.0.9.0","financial_services_analytical_applications_infrastructure >= 8.1.0.0, < 8.1.2.0","financial_services_behavior_detection_platform >= 8.0.6.0.0, <= 8.0.8.0","financial_services_behavior_detection_platform = 8.1.1.0","financial_services_behavior_detection_platform = 8.1.1.1","financial_services_behavior_detection_platform = 8.1.2.0","financial_services_crime_and_compliance_management_studio = 8.0.8.2.0","financial_services_crime_and_compliance_management_studio = 8.0.8.3.0","financial_services_enterprise_case_management = 8.0.7.1","financial_services_enterprise_case_management = 8.0.7.2.0","financial_services_enterprise_case_management = 8.0.8.0","financial_services_enterprise_case_management = 8.0.8.1","financial_services_enterprise_case_management = 8.1.1.0","financial_services_enterprise_case_management = 8.1.1.1","flexcube_universal_banking = 12.4.0","global_lifecycle_management_nextgen_oui_framework < 13.9.4.2.2","global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2","global_lifecycle_management_opatch < 12.2.0.1.30","health_sciences_information_manager >= 3.0.1, <= 3.0.5","health_sciences_information_manager = 3.0.0.1","ilearning = 6.2","ilearning = 6.3","peoplesoft_enterprise_peopletools = 8.58","peoplesoft_enterprise_peopletools = 8.59","primavera_gateway >= 17.7, <= 17.12.11","primavera_gateway >= 18.8.0, <= 18.8.14","primavera_gateway >= 19.12.0, <= 19.12.13","primavera_gateway >= 20.12.0, <= 20.12.8","product_lifecycle_analytics = 3.6.1","retail_bulk_data_integration = 16.0.3.0","retail_extract_transform_and_load = 13.2.8","retail_financial_integration = 14.1.3.2","retail_financial_integration = 15.0.3.1","retail_financial_integration = 16.0.3","retail_financial_integration = 19.0.1","retail_integration_bus = 14.1.3.2","retail_integration_bus = 15.0.3.1","retail_integration_bus = 16.0.3","retail_integration_bus = 19.0.1","retail_merchandising_system = 16.0.3","retail_merchandising_system = 19.0.1","retail_service_backbone = 14.1.3.2","retail_service_backbone = 15.0.3.1","retail_service_backbone = 16.0.3","retail_service_backbone = 19.0.1","weblogic_server = 12.2.1.3.0","weblogic_server = 12.2.1.4.0","weblogic_server = 14.1.1.0.0","active_iq_unified_manager"],"patched":["communications_element_manager 9.0","communications_session_report_manager 9.0","communications_session_route_manager 9.0","financial_services_analytical_applications_infrastructure 8.1.2.0","global_lifecycle_management_nextgen_oui_framework 13.9.4.2.2","global_lifecycle_management_opatch 12.2.0.1.30"],"published":"2022-01-24","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-23437","references":[{"url":"http://www.openwall.com/lists/oss-security/2022/01/24/3","label":"security@apache.org"},{"url":"https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20221028-0005/","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2022/01/24/3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20221028-0005/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.11615,"epssPercentile":0.95908,"ingestedAt":"2026-08-25T17:29:31.896Z","slug":"CVE-2022-23437","body":"## Overview\n\nThere's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.\n\n## Affected\n\n- `xerces-j <= 2.12.1`\n- `agile_engineering_data_management = 6.2.1.0`\n- `agile_product_lifecycle_management = 9.3.6`\n- `banking_deposits_and_lines_of_credit_servicing = 2.7`\n- `banking_party_management = 2.7.0`\n- `communications_asap = 7.3`\n- `communications_element_manager < 9.0`\n- `communications_session_report_manager < 9.0`\n- `communications_session_route_manager < 9.0`\n- `financial_services_analytical_applications_infrastructure >= 8.0.6.0.0, <= 8.0.9.0`\n- `financial_services_analytical_applications_infrastructure >= 8.1.0.0, < 8.1.2.0`\n- `financial_services_behavior_detection_platform >= 8.0.6.0.0, <= 8.0.8.0`\n- `financial_services_behavior_detection_platform = 8.1.1.0`\n- `financial_services_behavior_detection_platform = 8.1.1.1`\n- `financial_services_behavior_detection_platform = 8.1.2.0`\n- `financial_services_crime_and_compliance_management_studio = 8.0.8.2.0`\n- `financial_services_crime_and_compliance_management_studio = 8.0.8.3.0`\n- `financial_services_enterprise_case_management = 8.0.7.1`\n- `financial_services_enterprise_case_management = 8.0.7.2.0`\n- `financial_services_enterprise_case_management = 8.0.8.0`\n- `financial_services_enterprise_case_management = 8.0.8.1`\n- `financial_services_enterprise_case_management = 8.1.1.0`\n- `financial_services_enterprise_case_management = 8.1.1.1`\n- `flexcube_universal_banking = 12.4.0`\n- `global_lifecycle_management_nextgen_oui_framework < 13.9.4.2.2`\n- `global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2`\n- `global_lifecycle_management_opatch < 12.2.0.1.30`\n- `health_sciences_information_manager >= 3.0.1, <= 3.0.5`\n- `health_sciences_information_manager = 3.0.0.1`\n- `ilearning = 6.2`\n- `ilearning = 6.3`\n- `peoplesoft_enterprise_peopletools = 8.58`\n- `peoplesoft_enterprise_peopletools = 8.59`\n- `primavera_gateway >= 17.7, <= 17.12.11`\n- `primavera_gateway >= 18.8.0, <= 18.8.14`\n- `primavera_gateway >= 19.12.0, <= 19.12.13`\n- `primavera_gateway >= 20.12.0, <= 20.12.8`\n- `product_lifecycle_analytics = 3.6.1`\n- `retail_bulk_data_integration = 16.0.3.0`\n- `retail_extract_transform_and_load = 13.2.8`\n- `retail_financial_integration = 14.1.3.2`\n- `retail_financial_integration = 15.0.3.1`\n- `retail_financial_integration = 16.0.3`\n- `retail_financial_integration = 19.0.1`\n- `retail_integration_bus = 14.1.3.2`\n- `retail_integration_bus = 15.0.3.1`\n- `retail_integration_bus = 16.0.3`\n- `retail_integration_bus = 19.0.1`\n- `retail_merchandising_system = 16.0.3`\n- `retail_merchandising_system = 19.0.1`\n- `retail_service_backbone = 14.1.3.2`\n- `retail_service_backbone = 15.0.3.1`\n- `retail_service_backbone = 16.0.3`\n- `retail_service_backbone = 19.0.1`\n- `weblogic_server = 12.2.1.3.0`\n- `weblogic_server = 12.2.1.4.0`\n- `weblogic_server = 14.1.1.0.0`\n- `active_iq_unified_manager`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `communications_element_manager 9.0`\n- `communications_session_report_manager 9.0`\n- `communications_session_route_manager 9.0`\n- `financial_services_analytical_applications_infrastructure 8.1.2.0`\n- `global_lifecycle_management_nextgen_oui_framework 13.9.4.2.2`\n- `global_lifecycle_management_opatch 12.2.0.1.30`","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":35.8,"likelihood":2.3,"exploitation":0,"ransomware":0},"changes":[]}