CVE-2022-41404 - Denial of Service (DoS)

Severity: None2023-03-22

Security Advisories

Abstract

An issue in the fetch() method in the BasicProfile class of org.ini4j before v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

The Oxygen products incorporate org.ini4j as a third-party library. This advisory was opened to address the potential impact of this third-party library vulnerability.

Affected Products/Versions

ProductSeverityFixed Release Availability
Oxygen XML Web Author v25.0.2 and olderNone Oxygen XML Web Author 25.1.0 build 2023031320

Mitigation

None

Detail

CVE-2022-41404

Severity: High

CVSS Score: 7.5

The org.ini4j third-party library used by Oxygen XML products is an affected version mentioned in CVE-2022-41404 vulnerability description. However, the Oxygen products does not call the affected method. For that reason, Oxygen XML products are not affected by this vulnerability.

Starting with Oxygen XML Web Author v25.1.0 build 2023031320 org.ini4j library was removed.

List of Security Advisories