CVE Database
/

CVE-2022-34169

Back to search

CVE-2022-34169

Published: Jul 19, 2022

Modified: May 27, 2026

PUBLISHED

Description

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

VendorProductVersions

Apache Software Foundation

Apache Xalan-J

affected
Xalan-J - <= 2.7.2

References

DSA-5188
vendor-advisory
DSA-5192
vendor-advisory
FEDORA-2022-19b6f21746
vendor-advisory
FEDORA-2022-ae563934f7
vendor-advisory
FEDORA-2022-e573851f56
vendor-advisory
FEDORA-2022-d26586b419
vendor-advisory
FEDORA-2022-80afe2304a
vendor-advisory
FEDORA-2022-b76ab52e73
vendor-advisory
DSA-5256
vendor-advisory

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now