7.5
CVSSv3

CVE-2022-40152

Published: 16/09/2022 Updated: 09/02/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Description<!---->A flaw was found in the XStream package. This flaw allows an malicious user to cause a denial of service (DoS) in its target via XML serialization.A flaw was found in the XStream package. This flaw allows an malicious user to cause a denial of service (DoS) in its target via XML serialization.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xstream project xstream

fasterxml woodstox

Vendor Advisories

Debian Bug report logs - #1032089 libwoodstox-java: CVE-2022-40152 Package: src:libwoodstox-java; Maintainer for src:libwoodstox-java is Debian Java Maintainers &lt;pkg-java-maintainers@listsaliothdebianorg&gt;; Reported by: Moritz Mühlenhoff &lt;jmm@inutilorg&gt; Date: Mon, 27 Feb 2023 19:48:04 UTC Severity: important Tags ...
Debian Bug report logs - #1032091 py7zr: CVE-2022-44900 Package: src:py7zr; Maintainer for src:py7zr is Sandro Tosi &lt;morph@debianorg&gt;; Reported by: Moritz Mühlenhoff &lt;jmm@inutilorg&gt; Date: Mon, 27 Feb 2023 19:48:11 UTC Severity: grave Tags: security, upstream Reply or subscribe to this bug Toggle useless mes ...
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow This effect may support a denial of service attack (CVE-2022-40152) ...
Synopsis Important: Service Registry (container images) release and security update [243 GA] Type/Severity Security Advisory: Important Topic An update to the images for Red Hat Integration - Service Registry is now available from the Red Hat Container Catalog The purpose of this text-only errata is to inform you about the security issues ...
Synopsis Important: Red Hat Process Automation Manager 7134 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which ...
Synopsis Moderate: Red Hat Integration Camel Extensions For Quarkus 2132 Type/Severity Security Advisory: Moderate Topic Red Hat Integration Camel Extensions for Quarkus 2132 is now available The purpose of this text-only errata is to inform you about the security issues fixedRed Hat Product Security has rated this update as having an i ...
Synopsis Important: Red Hat Integration Camel for Spring Boot 3183 Patch 2 release Type/Severity Security Advisory: Important Topic Camel for Spring Boot 3183 Patch 2 release and security update is now availableRed Hat Product Security has rated this update as having an impact of Important A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 749 Security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat JBoss Enterprise Application Platform 74 for ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 749 Security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 74 Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Syste ...
Synopsis Important: jenkins and jenkins-2-plugins security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for jenkins and jenkins-2-plugins is now available for OpenShift Developer Tools and Services for ...
Description<!---->A flaw was found in the XStream package This flaw allows an attacker to cause a denial of service (DoS) in its target via XML serializationA flaw was found in the XStream package This flaw allows an attacker to cause a denial of service (DoS) in its target via XML serialization ...
Multiple vulnerabilities have been found in Hitachi Ops Center Common Services CVE-2020-8908, CVE-2020-14326, CVE-2020-25633, CVE-2020-36518, CVE-2021-20289, CVE-2021-21290, CVE-2021-46877, CVE-2022-3782, CVE-2022-4147, CVE-2022-40151, CVE-2022-40152, CVE-2022-41915, CVE-2022-41946, CVE-2022-41966, CVE-2023-0091, CVE-2023-1370, CVE-2023-28708 ...