CVE-2019-12415

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
apachepoi
𝑥
≤ 4.1.0
oracleapplication_testing_suite
12.5.0.3
oracleapplication_testing_suite
13.1.0.1
oracleapplication_testing_suite
13.2.0.1
oracleapplication_testing_suite
13.3.0.1
oraclebanking_enterprise_originations
2.7.0
oraclebanking_enterprise_originations
2.8.0
oraclebanking_enterprise_product_manufacturing
2.7.0
oraclebanking_enterprise_product_manufacturing
2.8.0
oraclebanking_payments
14.0.0
oraclebanking_payments
14.1.0
oraclebanking_platform
2.4.0
oraclebanking_platform
2.4.1
oraclebanking_platform
2.5.0
oraclebanking_platform
2.6.0
oraclebanking_platform
2.6.1
oraclebanking_platform
2.6.2
oraclebanking_platform
2.7.0
oraclebanking_platform
2.7.1
oraclebanking_platform
2.9.0
oraclebig_data_discovery
1.6
oracleendeca_information_discovery_studio
3.2.0
oracleenterprise_manager_base_platform
12.1.0.5
oracleenterprise_manager_base_platform
13.3.0.0
oracleenterprise_manager_base_platform
13.4.0.0
oracleenterprise_repository
12.1.3.0.0
oraclefinancial_services_analytical_applications_infrastructure
8.0.6 ≤
𝑥
≤ 8.0.9
oraclefinancial_services_market_risk_measurement_and_management
8.0.6
oraclefinancial_services_market_risk_measurement_and_management
8.0.8
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
oraclehyperion_infrastructure_technology
11.1.2.4
oracleinstantis_enterprisetrack
17.1
oracleinstantis_enterprisetrack
17.2
oracleinstantis_enterprisetrack
17.3
oracleinsurance_policy_administration_j2ee
11.0.2
oracleinsurance_policy_administration_j2ee
11.1.0
oracleinsurance_policy_administration_j2ee
11.2.0
oracleinsurance_rules_palette
10.2.0
oracleinsurance_rules_palette
10.2.4
oracleinsurance_rules_palette
11.0.2
oracleinsurance_rules_palette
11.1.0
oracleinsurance_rules_palette
11.2.0
oraclejdeveloper
12.2.1.4.0
oraclepeoplesoft_enterprise_peopletools
8.57
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepeoplesoft_enterprise_peopletools
8.59
oracleprimavera_gateway
17.12.6
oracleprimavera_gateway
18.8.8.1
oracleprimavera_unifier
17.7 ≤
𝑥
≤ 17.12
oracleprimavera_unifier
16.1
oracleprimavera_unifier
16.2
oracleprimavera_unifier
18.8
oracleprimavera_unifier
19.12
oracleretail_clearance_optimization_engine
14.0
oracleretail_order_broker
15.0
oracleretail_order_broker
16.0
oracleretail_predictive_application_server
15.0.3
oracleretail_predictive_application_server
16.0.3
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
oraclewebcenter_sites
12.2.1.3.0
oraclewebcenter_sites
12.2.1.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libapache-poi-java
bullseye
unimportant
bookworm
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libapache-poi-java
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
eoan
ignored
disco
ignored
bionic
needs-triage
xenial
needs-triage
trusty
dne
References