Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-14709
HistoryJan 26, 2022 - 12:00 a.m.

Apache Xerces Denial of Service Vulnerability

2022-01-2600:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
apache xerces
denial of service
xml parser
vulnerability
infinite loop
system resources

EPSS

0.005

Percentile

76.1%

A denial-of-service vulnerability in the XML parser in Apache Xerces Java version 2.12.1 and prior versions stems from a failure to properly process incoming error messages, which could be exploited by an attacker to cause a specially crafted XML document load to XercesJXML parser to wait in an infinite loop, which in turn consumes system resources for a long time.