AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-23437

MEDIUM · CVSS 6.5 EPSS 4.44%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-01-24 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It affects Apache, Java.

CVE
CVE-2022-23437
Severity
MEDIUM
CVSS
6.5
EPSS
4.44%
Apache Java

Original NVD Description

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)