SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-34169

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets.

HIGH 7.5EPSS 81.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 81.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
81.04% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-681
Affected
apache/xalan-java · debian/debian linux · oracle/graalvm · oracle/jdk · oracle/jre · oracle/openjdk · fedoraproject/fedora · netapp/7-mode transition tool · netapp/active iq unified manager · netapp/cloud insights acquisition unit · netapp/cloud secure agent · netapp/hci management node · netapp/oncommand insight · netapp/solidfire · netapp/hci compute node · azul/zulu
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.