SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-12415

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML…

MEDIUM 5.5EPSS 0.99%

Does this matter?

Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.

Description

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.99% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
apache/poi · oracle/application testing suite · oracle/banking enterprise originations · oracle/banking enterprise product manufacturing · oracle/banking payments · oracle/banking platform · oracle/big data discovery · oracle/communications diameter signaling router idih\ · oracle/endeca information discovery studio · oracle/enterprise manager base platform · oracle/enterprise repository · oracle/financial services analytical applications infrastructure · oracle/financial services market risk measurement and management · oracle/flexcube private banking · oracle/hyperion infrastructure technology · oracle/instantis enterprisetrack · oracle/insurance policy administration j2ee · oracle/insurance rules palette · oracle/jdeveloper · oracle/peoplesoft enterprise peopletools · +7 more
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.