In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

Project Subscriptions

Vendors Products
Application Testing Suite Subscribe
Banking Enterprise Originations Subscribe
Banking Enterprise Product Manufacturing Subscribe
Banking Payments Subscribe
Banking Platform Subscribe
Big Data Discovery Subscribe
Communications Diameter Signaling Router Idih\ Subscribe
Endeca Information Discovery Studio Subscribe
Enterprise Manager Base Platform Subscribe
Enterprise Repository Subscribe
Financial Services Analytical Applications Infrastructure Subscribe
Financial Services Market Risk Measurement And Management Subscribe
Flexcube Private Banking Subscribe
Hyperion Infrastructure Technology Subscribe
Instantis Enterprisetrack Subscribe
Insurance Policy Administration J2ee Subscribe
Insurance Rules Palette Subscribe
Jdeveloper Subscribe
Peoplesoft Enterprise Peopletools Subscribe
Primavera Gateway Subscribe
Primavera Unifier Subscribe
Retail Clearance Optimization Engine Subscribe
Retail Order Broker Subscribe
Retail Predictive Application Server Subscribe
Webcenter Portal Subscribe
Webcenter Sites Subscribe
Jboss Fuse Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3406 In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Github GHSA Github GHSA GHSA-9jwc-q6j3-8g9g Improper Restriction of XML External Entity Reference in Apache POI
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T23:17:40.071Z

Reserved: 2019-05-28T00:00:00.000Z

Link: CVE-2019-12415

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-23T20:15:12.707

Modified: 2024-11-21T04:22:47.553

Link: CVE-2019-12415

cve-icon Redhat

Severity : Low

Publid Date: 2020-02-13T00:00:00Z

Links: CVE-2019-12415 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses