CVE-2019-12415
23.10.2019, 20:15
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.Enginsight
Vendor | Product | Version |
---|---|---|
apache | poi | 𝑥 ≤ 4.1.0 |
oracle | application_testing_suite | 12.5.0.3 |
oracle | application_testing_suite | 13.1.0.1 |
oracle | application_testing_suite | 13.2.0.1 |
oracle | application_testing_suite | 13.3.0.1 |
oracle | banking_enterprise_originations | 2.7.0 |
oracle | banking_enterprise_originations | 2.8.0 |
oracle | banking_enterprise_product_manufacturing | 2.7.0 |
oracle | banking_enterprise_product_manufacturing | 2.8.0 |
oracle | banking_payments | 14.0.0 |
oracle | banking_payments | 14.1.0 |
oracle | banking_platform | 2.4.0 |
oracle | banking_platform | 2.4.1 |
oracle | banking_platform | 2.5.0 |
oracle | banking_platform | 2.6.0 |
oracle | banking_platform | 2.6.1 |
oracle | banking_platform | 2.6.2 |
oracle | banking_platform | 2.7.0 |
oracle | banking_platform | 2.7.1 |
oracle | banking_platform | 2.9.0 |
oracle | big_data_discovery | 1.6 |
oracle | endeca_information_discovery_studio | 3.2.0 |
oracle | enterprise_manager_base_platform | 12.1.0.5 |
oracle | enterprise_manager_base_platform | 13.3.0.0 |
oracle | enterprise_manager_base_platform | 13.4.0.0 |
oracle | enterprise_repository | 12.1.3.0.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.6 ≤ 𝑥 ≤ 8.0.9 |
oracle | financial_services_market_risk_measurement_and_management | 8.0.6 |
oracle | financial_services_market_risk_measurement_and_management | 8.0.8 |
oracle | flexcube_private_banking | 12.0.0 |
oracle | flexcube_private_banking | 12.1.0 |
oracle | hyperion_infrastructure_technology | 11.1.2.4 |
oracle | instantis_enterprisetrack | 17.1 |
oracle | instantis_enterprisetrack | 17.2 |
oracle | instantis_enterprisetrack | 17.3 |
oracle | insurance_policy_administration_j2ee | 11.0.2 |
oracle | insurance_policy_administration_j2ee | 11.1.0 |
oracle | insurance_policy_administration_j2ee | 11.2.0 |
oracle | insurance_rules_palette | 10.2.0 |
oracle | insurance_rules_palette | 10.2.4 |
oracle | insurance_rules_palette | 11.0.2 |
oracle | insurance_rules_palette | 11.1.0 |
oracle | insurance_rules_palette | 11.2.0 |
oracle | jdeveloper | 12.2.1.4.0 |
oracle | peoplesoft_enterprise_peopletools | 8.57 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
oracle | peoplesoft_enterprise_peopletools | 8.59 |
oracle | primavera_gateway | 17.12.6 |
oracle | primavera_gateway | 18.8.8.1 |
oracle | primavera_unifier | 17.7 ≤ 𝑥 ≤ 17.12 |
oracle | primavera_unifier | 16.1 |
oracle | primavera_unifier | 16.2 |
oracle | primavera_unifier | 18.8 |
oracle | primavera_unifier | 19.12 |
oracle | retail_clearance_optimization_engine | 14.0 |
oracle | retail_order_broker | 15.0 |
oracle | retail_order_broker | 16.0 |
oracle | retail_predictive_application_server | 15.0.3 |
oracle | retail_predictive_application_server | 16.0.3 |
oracle | webcenter_portal | 12.2.1.3.0 |
oracle | webcenter_portal | 12.2.1.4.0 |
oracle | webcenter_sites | 12.2.1.3.0 |
oracle | webcenter_sites | 12.2.1.4.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References