← back
CVE-2022-34169highCWE-681

Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets

43Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 81%
exploitation probability
81%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
11 products (48 components)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7 · Migration Toolkit for Applications 6 · Red Hat Build of Keycloak · Red Hat Fuse 7 · and others 6
no_fix_planned: Will not fix
Fixed
28 products (1,862 components)
Red Hat Enterprise Linux CRB (v. 8) · Red Hat CodeReady Linux Builder (v. 9) · Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux AppStream (v. 9) · Red Hat Enterprise Linux AppStream EUS (v.8.4) · and others 23
Not affected
9 products (27 components)because the vulnerable code is not present in the product
Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux 8 · Migration Toolkit for Runtimes · Red Hat AMQ Broker 7 · Red Hat Data Grid 8 · and others 4
In short

Apache Xalan's XSLT processor can be tricked by specially crafted stylesheets to generate corrupted Java code, allowing attackers to run arbitrary commands on the system.

Technical detail

An integer truncation vulnerability in Xalan's XSLTC compiler allows attackers to submit malicious XSLT stylesheets that corrupt generated Java bytecode, enabling arbitrary code execution with the privileges of the Java process. The vulnerability requires the application to process untrusted XSLT input.

Summary generated and translated by AI from the official description.
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N