PT-2019-4677 · Apache+1 · Apache Poi+1
Published
2019-10-20
·
Updated
2022-05-24
·
CVE-2019-12415
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache POI versions up to 4.1.0
Description
The issue is related to the XSSFExportToXml tool in Apache POI, which can be exploited to read files from the local filesystem or internal network resources via XML External Entity (XXE) Processing when converting user-provided Microsoft Excel documents. This is due to insufficient restrictions on XML external entities.
Recommendations
For Apache POI versions up to 4.1.0, consider disabling the XSSFExportToXml tool until a patch is available to prevent potential exploitation. Restrict access to sensitive files and network resources to minimize the risk of unauthorized access.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Poi
Debian