org.exist-db.thirdparty.xerces/xercesImpl… | Sonatype Guide

xercesImpl2.12.1

org.exist-db.thirdparty.xerces
jar
Published Jan 21, 2020 • Policy compliance
maven Registry
Developer Trust Score N/A
Recommended Version: x.y.z
Recommended upgrade that meets your policy.
Compare Versions

Overview

Versions 3
Vulnerabilities 3
Dependencies 1

Severity Count
Critical 1
High 0
Medium 2
Low 0

CVSS Score 0.0
EPSS Score 0.0
Malware All
KEV Status All
Known Exploited Not in KEV Catalog: No known exploits

Vulnerabilities

  1. CVE-2022-23437
    There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and previous versions.
    Severity Medium
    Published Jan 25, 2022

  2. sonatype-2017-0348
    sonatype-2017-0348 - xerces:xercesImpl - Denial of Service (DoS)
    Severity Medium
    Published Sep 15, 2017

  3. CVE-2017-7503
    It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
    Severity Critical
    Published Jul 12, 2017

org.exist-db.thirdparty.xerces/xercesImpl… | Sonatype Guide