Description
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Published: 2019-10-23
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-3406 In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Github GHSA Github GHSA GHSA-9jwc-q6j3-8g9g Improper Restriction of XML External Entity Reference in Apache POI
History

No history.

Subscriptions

Apache Poi
Oracle Application Testing Suite Banking Enterprise Originations Banking Enterprise Product Manufacturing Banking Payments Banking Platform Big Data Discovery Communications Diameter Signaling Router Idih\ Endeca Information Discovery Studio Enterprise Manager Base Platform Enterprise Repository Financial Services Analytical Applications Infrastructure Financial Services Market Risk Measurement And Management Flexcube Private Banking Hyperion Infrastructure Technology Instantis Enterprisetrack Insurance Policy Administration J2ee Insurance Rules Palette Jdeveloper Peoplesoft Enterprise Peopletools Primavera Gateway Primavera Unifier Retail Clearance Optimization Engine Retail Order Broker Retail Predictive Application Server Webcenter Portal Webcenter Sites
Redhat Jboss Fuse
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T23:17:40.071Z

Reserved: 2019-05-28T00:00:00.000Z

Link: CVE-2019-12415

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-23T20:15:12.707

Modified: 2024-11-21T04:22:47.553

Link: CVE-2019-12415

cve-icon Redhat

Severity : Low

Publid Date: 2020-02-13T00:00:00Z

Links: CVE-2019-12415 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses