Apache Xalan是美国阿帕奇(Apache)基金会的开源软件库。 Apache Xalan Java XSLT库存在输入验证错误漏洞,该漏洞源于在处理恶意的XSLT样式表时,存在整数截断问题。这可以用来破坏由内部XSLTC编译器生成的Java类文件并执行任意的Java字节码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Xalan-J | Xalan-J≤ 2.7.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Xalan-J | Xalan-J ~ 2.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | https://nvd.nist.gov/vuln/detail/CVE-2022-34169 | https://github.com/bor8/CVE-2022-34169 | POC Details |
| 2 | cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件 | https://github.com/flowerwind/AutoGenerateXalanPayload | POC Details |
| 3 | A PoC for CVE-2022-34169, for the SU_PWN challenge from SUCTF 2025 | https://github.com/Disnaming/CVE-2022-34169 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet