Rewterz
Rewterz Threat Update – Critical SonicWall RCE Bug Actively Targeted by Threat Actors
January 25, 2022
Rewterz
Rewterz Threat Alert – Donot APT Group – Active IOCs
January 25, 2022

Rewterz Threat Advisory – CVE-2022-23437 – Apache Xerces2 Java XML Parser Vulnerability

Severity

Medium

Analysis Summary

CVE-2022-23437

Apache Xerces2 Java XML Parser is vulnerable to a denial of service, caused by an infinite flaw in the XML parser. By persuading a victim to open a specially-crafted XML document payloads, a remote attacker could exploit this vulnerability to consume system resources for prolonged duration, and results in a denial of service condition.

Impact

  • Denial of Service

Affected Vendors

Apache

Affected Products

  • Apache Xerces2 Java XML Parser 2.12.1

Remediation

Upgrade to the latest version of Apache Xerces, available from the Apache Web site.

https://seclists.org/oss-sec/2022/q1/67