imPC@ndo IT

Tracker / CVE-2022-34169

CVE-2022-34169

High 7.5

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

Affected products and versions

apache xalan-java · … → 2.7.2
azul zulu
debian debian_linux
fedoraproject fedora
netapp 7-mode_transition_tool
netapp active_iq_unified_manager
netapp cloud_insights_acquisition_unit
netapp cloud_secure_agent
netapp hci_compute_node
netapp hci_management_node
netapp oncommand_insight
netapp solidfire
oracle graalvm
oracle jdk
oracle jre
oracle openjdk
oracle openjdk · 11 → 11.0.15
oracle openjdk · 13 → 13.0.11
oracle openjdk · 15 → 15.0.7
oracle openjdk · 17 → 17.0.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References