PT-2025-46560 · Apache · Apache Openoffice

Published

2025-11-11

·

Updated

2025-11-12

·

CVE-2025-64401

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache OpenOffice versions through 4.1.15
Description Apache OpenOffice had a missing authorization check that allowed an attacker to create a document that would load external links without user confirmation. Documents utilizing "floating frames" linked to external files would load the content of those frames without prompting the user for permission.
Recommendations Upgrade to version 4.1.16 to resolve this issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-15429
CVE-2025-64401

Affected Products

Apache Openoffice