org.exist-db.thirdparty.xerces/xercesImpl… | Sonatype Guide
xercesImpl2.12.1
org.exist-db.thirdparty.xerces
jar
Published Jan 21, 2020 • Policy compliance
maven Registry
Developer Trust Score N/A
Recommended Version: x.y.z
Recommended upgrade that meets your policy.
Compare Versions
Overview
Versions 3
Vulnerabilities 3
Dependencies 1
| Severity | Count |
|---|---|
| Critical | 1 |
| High | 0 |
| Medium | 2 |
| Low | 0 |
CVSS Score 0.0
EPSS Score 0.0
Malware All
KEV Status All
Known Exploited Not in KEV Catalog: No known exploits
Vulnerabilities
CVE-2022-23437
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and previous versions.
Severity Medium
Published Jan 25, 2022sonatype-2017-0348
sonatype-2017-0348 - xerces:xercesImpl - Denial of Service (DoS)
Severity Medium
Published Sep 15, 2017CVE-2017-7503
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
Severity Critical
Published Jul 12, 2017
org.exist-db.thirdparty.xerces/xercesImpl… | Sonatype Guide