Cybersource imports xalan-2.7.2.jar, which has a vulnerability noted in CVE-2022-34169 https://nvd.nist.gov/vuln/detail/CVE-2022-34169 The issue is fixed in xalan-2.7.3. Would like to see if cybersource could be updated accordingly