The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
2022-07-19T18:15:11.740
2024-11-21T07:08:59.400
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | xalan-java | ≤ 2.7.2 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |
Application | oracle | graalvm | 20.3.6 | Yes |
Application | oracle | graalvm | 21.3.2 | Yes |
Application | oracle | graalvm | 22.1.0 | Yes |
Application | oracle | jdk | 1.7.0 | Yes |
Application | oracle | jdk | 1.8.0 | Yes |
Application | oracle | jdk | 11.0.15.1 | Yes |
Application | oracle | jdk | 17.0.3.1 | Yes |
Application | oracle | jdk | 18.0.1.1 | Yes |
Application | oracle | jre | 1.7.0 | Yes |
Application | oracle | jre | 1.8.0 | Yes |
Application | oracle | jre | 11.0.15.1 | Yes |
Application | oracle | jre | 17.0.3.1 | Yes |
Application | oracle | jre | 18.0.1.1 | Yes |
Application | oracle | openjdk | ≤ 11.0.15 | Yes |
Application | oracle | openjdk | ≤ 13.0.11 | Yes |
Application | oracle | openjdk | ≤ 15.0.7 | Yes |
Application | oracle | openjdk | ≤ 17.0.3 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 7 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 8 | Yes |
Application | oracle | openjdk | 18 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |
Operating System | fedoraproject | fedora | 36 | Yes |
Application | netapp | 7-mode_transition_tool | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | cloud_insights_acquisition_unit | - | Yes |
Application | netapp | cloud_secure_agent | - | Yes |
Application | netapp | hci_management_node | - | Yes |
Application | netapp | oncommand_insight | - | Yes |
Application | netapp | solidfire | - | Yes |
Hardware | netapp | hci_compute_node | - | Yes |
Application | azul | zulu | 6.47 | Yes |
Application | azul | zulu | 7.54 | Yes |
Application | azul | zulu | 8.62 | Yes |
Application | azul | zulu | 11.56 | Yes |
Application | azul | zulu | 13.48 | Yes |
Application | azul | zulu | 15.40 | Yes |
Application | azul | zulu | 17.34 | Yes |
Application | azul | zulu | 18.30 | Yes |