org.exist-db.thirdparty.xerces/xercesImpl… | Sonatype Guide

xercesImpl2.12.0

org.exist-db.thirdparty.xerces

jar

Published Apr 4, 2019 • Policy compliance

maven Registry

Developer Trust Score

N/A

Recommended Version: x.y.z

Recommended upgrade that meets your policy.

Compare Versions

Overview

Versions: 3
Vulnerabilities: 3
Dependencies: 1

Severity

CVSS Score

0.0

EPSS Score

0.0

Malware

All

KEV Status

All
Known Exploited: No known exploits
Published: All
Last 7 days
Last 30 days
Last 60 days
Last 90 days
Last 6 months
Last year
Last 2 years

Vulnerabilities

  1. CVE-2022-23437
    There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
    Severity: Medium
    Published: Jan 25, 2022

  2. sonatype-2017-0348
    xerces:xercesImpl - Denial of Service (DoS)
    Severity: Medium
    Published: Sep 15, 2017

  3. CVE-2017-7503
    It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
    Severity: Critical
    Published: Jul 12, 2017

org.exist-db.thirdparty.xerces/xercesImpl… | Sonatype Guide