SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-2625

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and…

MEDIUM 5.0EPSS 30.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 30.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
30.38% probability · 98th percentile
CISA KEV
Not listed
Affected
oracle/jdk · fedoraproject/fedora · opensuse/opensuse · suse/linux enterprise server · debian/debian linux · canonical/ubuntu linux · oracle/primavera p6 enterprise project portfolio management · oracle/primavera web services · apache/xerces2 java
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.