CVE-2019-12415
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Affected (65)
Products: Apache: Poi · Oracle: Application Testing Suite, Banking Enterprise Originations, Banking Enterprise Product Manufacturing, Banking Payments, Banking Platform, Big Data Discovery, Communications Diameter Signaling Router Idih\, Endeca Information Discovery Studio, Enterprise Manager Base Platform, Enterprise Repository, Financial Services Analytical Applications Infrastructure, Financial Services Market Risk Measurement And Management, Flexcube Private Banking, Hyperion Infrastructure Technology, Instantis Enterprisetrack, Insurance Policy Administration J2ee, Insurance Rules Palette, Jdeveloper, Peoplesoft Enterprise Peopletools, Primavera Gateway, Primavera Unifier, Retail Clearance Optimization Engine, Retail Order Broker, Retail Predictive Application Server, Webcenter Portal, Webcenter Sites
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.5.0.3 | |
| Version 2.7.0 | |
| Version 2.7.0 | |
| Version 14.0.0 | |
| Version 2.4.0 | |
| Version 1.6 | |
| All versions | |
| Version 3.2.0 | |
| Version 12.1.0.5 | |
| Version 12.1.3.0.0 | |
| From 8.0.6 to 8.0.9 | |
| Version 8.0.6 | |
| Version 12.0.0 | |
| Version 11.1.2.4 | |
| Version 17.1 | |
| Version 11.0.2 | |
| Version 10.2.0 | |
| Version 12.2.1.4.0 | |
| Version 8.57 | |
| Version 17.12.6 | |
| From 17.7 to 17.12 | |
| Version 14.0 | |
| Version 15.0 | |
| Version 15.0.3 | |
| Version 12.2.1.3.0 | |
| Version 12.2.1.3.0 |
References (26)
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.