← Back

CVE-2019-12415

nvd nist
Published: Oct 23, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

Affected (65)

Products: Apache: Poi · Oracle: Application Testing Suite, Banking Enterprise Originations, Banking Enterprise Product Manufacturing, Banking Payments, Banking Platform, Big Data Discovery, Communications Diameter Signaling Router Idih\, Endeca Information Discovery Studio, Enterprise Manager Base Platform, Enterprise Repository, Financial Services Analytical Applications Infrastructure, Financial Services Market Risk Measurement And Management, Flexcube Private Banking, Hyperion Infrastructure Technology, Instantis Enterprisetrack, Insurance Policy Administration J2ee, Insurance Rules Palette, Jdeveloper, Peoplesoft Enterprise Peopletools, Primavera Gateway, Primavera Unifier, Retail Clearance Optimization Engine, Retail Order Broker, Retail Predictive Application Server, Webcenter Portal, Webcenter Sites
1 product
Poi
26 products
Application Testing Suite
Banking Enterprise Originations
Banking Payments
Banking Platform
Big Data Discovery
Enterprise Manager Base Platform
Enterprise Repository
Flexcube Private Banking
Instantis Enterprisetrack
Insurance Rules Palette
Jdeveloper
Peoplesoft Enterprise Peopletools
Primavera Gateway
Primavera Unifier
Retail Order Broker
Webcenter Portal
Webcenter Sites
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.1.0
Configuration B
64 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 12.5.0.3
Version 13.1.0.1
Version 13.2.0.1
Version 13.3.0.1
Oracle
Version 2.7.0
Version 2.8.0
Oracle
Version 2.7.0
Version 2.8.0
Oracle
Version 14.0.0
Version 14.1.0
Oracle
Version 2.4.0
Version 2.4.1
Version 2.5.0
Version 2.6.0
Version 2.6.1
Version 2.6.2
Version 2.7.0
Version 2.7.1
Version 2.9.0
Version 1.6
Oracle
All versions
All versions
Version 3.2.0
Oracle
Version 12.1.0.5
Version 13.3.0.0
Version 13.4.0.0
Version 12.1.3.0.0
From 8.0.6 to 8.0.9
Oracle
Version 8.0.6
Version 8.0.8
Oracle
Version 12.0.0
Version 12.1.0
Version 11.1.2.4
Oracle
Version 17.1
Version 17.2
Version 17.3
Oracle
Version 11.0.2
Version 11.1.0
Version 11.2.0
Oracle
Version 10.2.0
Version 10.2.4
Version 11.0.2
Version 11.1.0
Version 11.2.0
Version 12.2.1.4.0
Oracle
Version 8.57
Version 8.58
Version 8.59
Oracle
Version 17.12.6
Version 18.8.8.1
Oracle
From 17.7 to 17.12
Version 16.1
Version 16.2
Version 18.8
Version 19.12
Version 14.0
Oracle
Version 15.0
Version 16.0
Oracle
Version 15.0.3
Version 16.0.3
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0

References (26)

Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.