CVE-2016-5000
MEDIUMApache Poi < 3.13 - XXE
Title source: ruleDescription
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
References (6)
Scores
CVSS v3
5.5
EPSS
0.0033
EPSS Percentile
55.6%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Classification
CWE
CWE-611
Status
draft
Affected Products (2)
apache/poi
< 3.13
org.apache.poi/poi-examples
< 3.14Maven
Timeline
Published
Aug 05, 2016
Tracked Since
Feb 18, 2026