PT-2025-46582 · Apache · Apache Openoffice

Published

2025-11-12

·

Updated

2025-11-12

·

CVE-2025-64402

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache OpenOffice versions through 4.1.15
Description Apache OpenOffice documents can contain links. A missing authorization check in Apache OpenOffice allowed an attacker to create a document that would load external links without user confirmation. Specifically, documents utilizing "OLE objects" linked to external files would load the contents of those files without prompting the user for permission.
Recommendations Upgrade to version 4.1.16 to resolve this issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-15431
CVE-2025-64402

Affected Products

Apache Openoffice