There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade xerces-j2Upgrade xerces-j2-demoUpgrade xerces-j2-javadoc | May 13, 2025 | Jan 24, 2022 |
| Debian | — | Upgrade libxerces2-java | Apr 28, 2025 | Jan 24, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade xerces-j2 | May 25, 2022 | Jan 24, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade xerces-j2 | Apr 26, 2022 | Jan 24, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade xerces-j2 | Apr 26, 2022 | Jan 24, 2022 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 34012040 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 34011596 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 34010914 for version 12.2.1.3.0. | Jul 25, 2022 | Jan 24, 2022 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Jan 24, 2022 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Jan 24, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 24, 2022 |
| Suse | — | Upgrade xerces-j2-demoUpgrade xerces-j2-javadocUpgrade xerces-j2Upgrade xerces-j2-xml-resolverUpgrade xerces-j2-scriptsUpgrade xerces-j2-xml-apis | Feb 19, 2022 | Jan 24, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub