org.exist-db.thirdparty.xerces/xercesImpl… | Sonatype Guide
xercesImpl2.12.0
org.exist-db.thirdparty.xerces
jar
Published Apr 4, 2019 • Policy compliance
Developer Trust Score
N/A
Recommended Version: x.y.z
Recommended upgrade that meets your policy.
Overview
Versions: 3
Vulnerabilities: 3
Dependencies: 1
Severity
- Critical (1)
- High (0)
- Medium (2)
- Low (0)
CVSS Score
0.0
EPSS Score
0.0
Malware
All
KEV Status
All
Known Exploited: No known exploits
Published: All
Last 7 days
Last 30 days
Last 60 days
Last 90 days
Last 6 months
Last year
Last 2 years
Vulnerabilities
CVE-2022-23437
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
Severity: Medium
Published: Jan 25, 2022sonatype-2017-0348
xerces:xercesImpl - Denial of Service (DoS)
Severity: Medium
Published: Sep 15, 2017CVE-2017-7503
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
Severity: Critical
Published: Jul 12, 2017
org.exist-db.thirdparty.xerces/xercesImpl… | Sonatype Guide