VDB
DEBIAN-CVE-2022-34169
DEBIAN-CVE-2022-34169
PUBLISHED
CVSS 7.5 HIGH
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | openjdk-11 | 11.0.14.1+1-1, 11.0.14.1+1, 11.0.15+10 |
| Debian:14 | bcel | 0, 0, 0 |
| Debian:13 | bcel | 0, 0, 0 |
| Debian:11 | bcel | 6.5.0-1, 0, 6.5.0-1 |
| Debian:12 | bcel | 0, 0, 0 |
| Debian:11 | openjdk-17 | *, 0, * |
| Debian:12 | openjdk-17 | 0, 0, 0 |
Exploit Intelligence
- A PoC for CVE-2022-34169, for the SU_PWN challenge from SUCTF 2025 (github-poc-repo)
- A PoC for CVE-2022-34169, for the SU_PWN challenge from SUCTF 2025 (github-poc)
- cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件 (github-poc)
- https://nvd.nist.gov/vuln/detail/CVE-2022-34169 (github-poc)
Timeline
- Jul 19, 2022 CVE Published
- Apr 28, 2026 CVE Updated