CVE-2022-41404 - Denial of Service (DoS)
Severity: None2023-03-22
Abstract
An issue in the fetch() method in the BasicProfile class of org.ini4j before v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
The Oxygen products incorporate org.ini4j as a third-party library. This advisory was opened to address the potential impact of this third-party library vulnerability.
Affected Products/Versions
Product | Severity | Fixed Release Availability |
Oxygen XML Web Author v25.0.2 and older | None | Oxygen XML Web Author 25.1.0 build 2023031320 |
Detail
CVE-2022-41404
Severity: High
CVSS Score: 7.5
The org.ini4j third-party library used by Oxygen XML products is an affected version mentioned in CVE-2022-41404 vulnerability description. However, the Oxygen products does not call the affected method. For that reason, Oxygen XML products are not affected by this vulnerability.
Starting with Oxygen XML Web Author v25.1.0 build 2023031320 org.ini4j library was removed.