AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-2838

MEDIUM · CVSS 5.3 EPSS 0.47%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-08-16 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-2838
Severity
MEDIUM
CVSS
5.3
EPSS
0.47%
Apache

Original NVD Description

In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests.