PT-2019-4677 · Apache+1 · Apache Poi+1

Published

2019-10-20

·

Updated

2022-05-24

·

CVE-2019-12415

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache POI versions up to 4.1.0
Description The issue is related to the XSSFExportToXml tool in Apache POI, which can be exploited to read files from the local filesystem or internal network resources via XML External Entity (XXE) Processing when converting user-provided Microsoft Excel documents. This is due to insufficient restrictions on XML external entities.
Recommendations For Apache POI versions up to 4.1.0, consider disabling the XSSFExportToXml tool until a patch is available to prevent potential exploitation. Restrict access to sensitive files and network resources to minimize the risk of unauthorized access.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00970
CVE-2019-12415
GHSA-9JWC-Q6J3-8G9G

Affected Products

Apache Poi
Debian