The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/34xxx/CVE-2022-34169.json",
"cna_assigner": "apache",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "Xalan-J"
},
{
"last_affected": "2.7.2"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"cpe": [
"cpe:2.3:a:oracle:graalvm:20.3.6:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:oracle:graalvm:21.3.2:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:oracle:graalvm:22.1.0:*:*:*:enterprise:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "20.3.6"
},
{
"last_affected": "21.3.2"
},
{
"last_affected": "22.1.0"
}
],
"source": "CPE_STRING"
}{
"cpe": [
"cpe:2.3:a:oracle:openjdk:7:update101:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update111:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update121:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update131:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update141:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update25:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update40:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update45:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update51:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update55:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update60:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update65:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update67:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update72:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update76:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update80:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update85:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update91:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update95:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update97:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update99:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update101:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update102:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update11:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update111:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update112:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update20:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update25:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update31:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update40:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update45:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update51:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update60:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update65:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update66:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update71:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update72:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update73:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update74:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update77:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update91:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update92:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:18:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "7-update101"
},
{
"last_affected": "7-update111"
},
{
"last_affected": "7-update121"
},
{
"last_affected": "7-update131"
},
{
"last_affected": "7-update141"
},
{
"last_affected": "7-update25"
},
{
"last_affected": "7-update40"
},
{
"last_affected": "7-update45"
},
{
"last_affected": "7-update51"
},
{
"last_affected": "7-update55"
},
{
"last_affected": "7-update60"
},
{
"last_affected": "7-update65"
},
{
"last_affected": "7-update67"
},
{
"last_affected": "7-update72"
},
{
"last_affected": "7-update76"
},
{
"last_affected": "7-update80"
},
{
"last_affected": "7-update85"
},
{
"last_affected": "7-update91"
},
{
"last_affected": "7-update95"
},
{
"last_affected": "7-update97"
},
{
"last_affected": "7-update99"
},
{
"last_affected": "8-update101"
},
{
"last_affected": "8-update102"
},
{
"last_affected": "8-update11"
},
{
"last_affected": "8-update111"
},
{
"last_affected": "8-update112"
},
{
"last_affected": "8-update20"
},
{
"last_affected": "8-update25"
},
{
"last_affected": "8-update31"
},
{
"last_affected": "8-update40"
},
{
"last_affected": "8-update45"
},
{
"last_affected": "8-update51"
},
{
"last_affected": "8-update60"
},
{
"last_affected": "8-update65"
},
{
"last_affected": "8-update66"
},
{
"last_affected": "8-update71"
},
{
"last_affected": "8-update72"
},
{
"last_affected": "8-update73"
},
{
"last_affected": "8-update74"
},
{
"last_affected": "8-update77"
},
{
"last_affected": "8-update91"
},
{
"last_affected": "8-update92"
},
{
"last_affected": "18"
}
],
"source": "CPE_STRING"
}{
"cpe": [
"cpe:2.3:a:oracle:openjdk:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update101:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update111:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update121:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update131:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update141:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update25:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update40:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update45:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update51:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update55:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update60:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update65:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update67:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update72:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update76:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update80:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update85:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update91:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update95:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update97:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update99:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update101:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update102:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update11:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update111:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update112:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update20:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update25:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update31:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update40:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update45:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update51:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update60:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update65:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update66:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update71:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update72:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update73:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update74:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update77:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update91:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update92:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "15"
},
{
"last_affected": "15.0.7"
},
{
"introduced": "0"
},
{
"last_affected": "7-update101"
},
{
"last_affected": "7-update111"
},
{
"last_affected": "7-update121"
},
{
"last_affected": "7-update131"
},
{
"last_affected": "7-update141"
},
{
"last_affected": "7-update25"
},
{
"last_affected": "7-update40"
},
{
"last_affected": "7-update45"
},
{
"last_affected": "7-update51"
},
{
"last_affected": "7-update55"
},
{
"last_affected": "7-update60"
},
{
"last_affected": "7-update65"
},
{
"last_affected": "7-update67"
},
{
"last_affected": "7-update72"
},
{
"last_affected": "7-update76"
},
{
"last_affected": "7-update80"
},
{
"last_affected": "7-update85"
},
{
"last_affected": "7-update91"
},
{
"last_affected": "7-update95"
},
{
"last_affected": "7-update97"
},
{
"last_affected": "7-update99"
},
{
"last_affected": "8-update101"
},
{
"last_affected": "8-update102"
},
{
"last_affected": "8-update11"
},
{
"last_affected": "8-update111"
},
{
"last_affected": "8-update112"
},
{
"last_affected": "8-update20"
},
{
"last_affected": "8-update25"
},
{
"last_affected": "8-update31"
},
{
"last_affected": "8-update40"
},
{
"last_affected": "8-update45"
},
{
"last_affected": "8-update51"
},
{
"last_affected": "8-update60"
},
{
"last_affected": "8-update65"
},
{
"last_affected": "8-update66"
},
{
"last_affected": "8-update71"
},
{
"last_affected": "8-update72"
},
{
"last_affected": "8-update73"
},
{
"last_affected": "8-update74"
},
{
"last_affected": "8-update77"
},
{
"last_affected": "8-update91"
},
{
"last_affected": "8-update92"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}{
"cpe": [
"cpe:2.3:a:oracle:openjdk:7:update101:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update111:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update121:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update131:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update141:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update25:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update40:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update45:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update51:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update55:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update60:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update65:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update67:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update72:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update76:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update80:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update85:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update91:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update95:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update97:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:7:update99:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update101:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update102:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update11:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update111:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update112:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update121:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update131:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update20:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update25:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update31:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update40:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update45:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update51:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update60:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update65:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update66:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update71:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update72:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update73:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update74:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update77:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update91:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update92:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "7-update101"
},
{
"last_affected": "7-update111"
},
{
"last_affected": "7-update121"
},
{
"last_affected": "7-update131"
},
{
"last_affected": "7-update141"
},
{
"last_affected": "7-update25"
},
{
"last_affected": "7-update40"
},
{
"last_affected": "7-update45"
},
{
"last_affected": "7-update51"
},
{
"last_affected": "7-update55"
},
{
"last_affected": "7-update60"
},
{
"last_affected": "7-update65"
},
{
"last_affected": "7-update67"
},
{
"last_affected": "7-update72"
},
{
"last_affected": "7-update76"
},
{
"last_affected": "7-update80"
},
{
"last_affected": "7-update85"
},
{
"last_affected": "7-update91"
},
{
"last_affected": "7-update95"
},
{
"last_affected": "7-update97"
},
{
"last_affected": "7-update99"
},
{
"last_affected": "8-update101"
},
{
"last_affected": "8-update102"
},
{
"last_affected": "8-update11"
},
{
"last_affected": "8-update111"
},
{
"last_affected": "8-update112"
},
{
"last_affected": "8-update121"
},
{
"last_affected": "8-update131"
},
{
"last_affected": "8-update20"
},
{
"last_affected": "8-update25"
},
{
"last_affected": "8-update31"
},
{
"last_affected": "8-update40"
},
{
"last_affected": "8-update45"
},
{
"last_affected": "8-update51"
},
{
"last_affected": "8-update60"
},
{
"last_affected": "8-update65"
},
{
"last_affected": "8-update66"
},
{
"last_affected": "8-update71"
},
{
"last_affected": "8-update72"
},
{
"last_affected": "8-update73"
},
{
"last_affected": "8-update74"
},
{
"last_affected": "8-update77"
},
{
"last_affected": "8-update91"
},
{
"last_affected": "8-update92"
}
],
"source": "CPE_STRING"
}