---
id: CVE-2022-23437
title: >-
  There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser
  when handling specially crafted XML document payloads
summary: >-
  There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser
  when handling specially crafted XML document payloads. This causes, the
  XercesJ XML parser to wait in an infinite loop, which may sometimes consume
  system resourc…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-835
vendor: apache
product: xerces-j
affected:
  - xerces-j <= 2.12.1
  - agile_engineering_data_management = 6.2.1.0
  - agile_product_lifecycle_management = 9.3.6
  - banking_deposits_and_lines_of_credit_servicing = 2.7
  - banking_party_management = 2.7.0
  - communications_asap = 7.3
  - communications_element_manager < 9.0
  - communications_session_report_manager < 9.0
  - communications_session_route_manager < 9.0
  - >-
    financial_services_analytical_applications_infrastructure >= 8.0.6.0.0, <=
    8.0.9.0
  - >-
    financial_services_analytical_applications_infrastructure >= 8.1.0.0, <
    8.1.2.0
  - 'financial_services_behavior_detection_platform >= 8.0.6.0.0, <= 8.0.8.0'
  - financial_services_behavior_detection_platform = 8.1.1.0
  - financial_services_behavior_detection_platform = 8.1.1.1
  - financial_services_behavior_detection_platform = 8.1.2.0
  - financial_services_crime_and_compliance_management_studio = 8.0.8.2.0
  - financial_services_crime_and_compliance_management_studio = 8.0.8.3.0
  - financial_services_enterprise_case_management = 8.0.7.1
  - financial_services_enterprise_case_management = 8.0.7.2.0
  - financial_services_enterprise_case_management = 8.0.8.0
  - financial_services_enterprise_case_management = 8.0.8.1
  - financial_services_enterprise_case_management = 8.1.1.0
  - financial_services_enterprise_case_management = 8.1.1.1
  - flexcube_universal_banking = 12.4.0
  - global_lifecycle_management_nextgen_oui_framework < 13.9.4.2.2
  - global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2
  - global_lifecycle_management_opatch < 12.2.0.1.30
  - 'health_sciences_information_manager >= 3.0.1, <= 3.0.5'
  - health_sciences_information_manager = 3.0.0.1
  - ilearning = 6.2
  - ilearning = 6.3
  - peoplesoft_enterprise_peopletools = 8.58
  - peoplesoft_enterprise_peopletools = 8.59
  - 'primavera_gateway >= 17.7, <= 17.12.11'
  - 'primavera_gateway >= 18.8.0, <= 18.8.14'
  - 'primavera_gateway >= 19.12.0, <= 19.12.13'
  - 'primavera_gateway >= 20.12.0, <= 20.12.8'
  - product_lifecycle_analytics = 3.6.1
  - retail_bulk_data_integration = 16.0.3.0
  - retail_extract_transform_and_load = 13.2.8
  - retail_financial_integration = 14.1.3.2
  - retail_financial_integration = 15.0.3.1
  - retail_financial_integration = 16.0.3
  - retail_financial_integration = 19.0.1
  - retail_integration_bus = 14.1.3.2
  - retail_integration_bus = 15.0.3.1
  - retail_integration_bus = 16.0.3
  - retail_integration_bus = 19.0.1
  - retail_merchandising_system = 16.0.3
  - retail_merchandising_system = 19.0.1
  - retail_service_backbone = 14.1.3.2
  - retail_service_backbone = 15.0.3.1
  - retail_service_backbone = 16.0.3
  - retail_service_backbone = 19.0.1
  - weblogic_server = 12.2.1.3.0
  - weblogic_server = 12.2.1.4.0
  - weblogic_server = 14.1.1.0.0
  - active_iq_unified_manager
patched:
  - communications_element_manager 9.0
  - communications_session_report_manager 9.0
  - communications_session_route_manager 9.0
  - financial_services_analytical_applications_infrastructure 8.1.2.0
  - global_lifecycle_management_nextgen_oui_framework 13.9.4.2.2
  - global_lifecycle_management_opatch 12.2.0.1.30
published: '2022-01-24'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-23437'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2022/01/24/3'
    label: security@apache.org
  - url: 'https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl'
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20221028-0005/'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2022/01/24/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20221028-0005/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.11615
epssPercentile: 0.95908
ingestedAt: '2026-08-25T17:29:31.896Z'
---

## Overview

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

## Affected

- `xerces-j <= 2.12.1`
- `agile_engineering_data_management = 6.2.1.0`
- `agile_product_lifecycle_management = 9.3.6`
- `banking_deposits_and_lines_of_credit_servicing = 2.7`
- `banking_party_management = 2.7.0`
- `communications_asap = 7.3`
- `communications_element_manager < 9.0`
- `communications_session_report_manager < 9.0`
- `communications_session_route_manager < 9.0`
- `financial_services_analytical_applications_infrastructure >= 8.0.6.0.0, <= 8.0.9.0`
- `financial_services_analytical_applications_infrastructure >= 8.1.0.0, < 8.1.2.0`
- `financial_services_behavior_detection_platform >= 8.0.6.0.0, <= 8.0.8.0`
- `financial_services_behavior_detection_platform = 8.1.1.0`
- `financial_services_behavior_detection_platform = 8.1.1.1`
- `financial_services_behavior_detection_platform = 8.1.2.0`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.2.0`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.3.0`
- `financial_services_enterprise_case_management = 8.0.7.1`
- `financial_services_enterprise_case_management = 8.0.7.2.0`
- `financial_services_enterprise_case_management = 8.0.8.0`
- `financial_services_enterprise_case_management = 8.0.8.1`
- `financial_services_enterprise_case_management = 8.1.1.0`
- `financial_services_enterprise_case_management = 8.1.1.1`
- `flexcube_universal_banking = 12.4.0`
- `global_lifecycle_management_nextgen_oui_framework < 13.9.4.2.2`
- `global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2`
- `global_lifecycle_management_opatch < 12.2.0.1.30`
- `health_sciences_information_manager >= 3.0.1, <= 3.0.5`
- `health_sciences_information_manager = 3.0.0.1`
- `ilearning = 6.2`
- `ilearning = 6.3`
- `peoplesoft_enterprise_peopletools = 8.58`
- `peoplesoft_enterprise_peopletools = 8.59`
- `primavera_gateway >= 17.7, <= 17.12.11`
- `primavera_gateway >= 18.8.0, <= 18.8.14`
- `primavera_gateway >= 19.12.0, <= 19.12.13`
- `primavera_gateway >= 20.12.0, <= 20.12.8`
- `product_lifecycle_analytics = 3.6.1`
- `retail_bulk_data_integration = 16.0.3.0`
- `retail_extract_transform_and_load = 13.2.8`
- `retail_financial_integration = 14.1.3.2`
- `retail_financial_integration = 15.0.3.1`
- `retail_financial_integration = 16.0.3`
- `retail_financial_integration = 19.0.1`
- `retail_integration_bus = 14.1.3.2`
- `retail_integration_bus = 15.0.3.1`
- `retail_integration_bus = 16.0.3`
- `retail_integration_bus = 19.0.1`
- `retail_merchandising_system = 16.0.3`
- `retail_merchandising_system = 19.0.1`
- `retail_service_backbone = 14.1.3.2`
- `retail_service_backbone = 15.0.3.1`
- `retail_service_backbone = 16.0.3`
- `retail_service_backbone = 19.0.1`
- `weblogic_server = 12.2.1.3.0`
- `weblogic_server = 12.2.1.4.0`
- `weblogic_server = 14.1.1.0.0`
- `active_iq_unified_manager`

## Remediation

Upgrade past the affected range:

- `communications_element_manager 9.0`
- `communications_session_report_manager 9.0`
- `communications_session_route_manager 9.0`
- `financial_services_analytical_applications_infrastructure 8.1.2.0`
- `global_lifecycle_management_nextgen_oui_framework 13.9.4.2.2`
- `global_lifecycle_management_opatch 12.2.0.1.30`
