Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-34169 Details

Description

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://packetstormsecurity.com/files/168186/Xalan-J-XSLTC-Integer-Truncation.html CVEThird Party AdvisoryVDB Entry
https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kyw CVEIssue TrackingMailing ListVendor Advisory
https://lists.apache.org/thread/2qvl7r43wb4t8p9dd9om1bnkssk07sn8 CVEIssue TrackingMailing ListVendor Advisory
https://lists.debian.org/debian-lts-announce/2022/10/msg00024.html CVEMailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/ CVE

see all 48 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-681Incorrect Conversion between Numeric Types[email protected]
CWE-681Incorrect Conversion between Numeric TypesCISA-ADP

Affected Products

ProductVersions

Change History

28 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-34169
NVD Published Date:
Jul 19, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2022-34169 Details - Not Deferred