CVE-2019-12415

MEDIUM

Apache POI < 4.1.0 - XML External Entity Injection via XSSFExportToXml

Title source: llm
STIX 2.1

Description

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

References (13)

Core 13
Core References
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2020.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2020.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2021.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 10.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (49)
apache/poi < 4.1.0
oracle/application_testing_suite 12.5.0.3
oracle/application_testing_suite 13.1.0.1
oracle/application_testing_suite 13.2.0.1
oracle/application_testing_suite 13.3.0.1
oracle/banking_enterprise_originations 2.7.0
oracle/banking_enterprise_originations 2.8.0
oracle/banking_enterprise_product_manufacturing 2.7.0
oracle/banking_enterprise_product_manufacturing 2.8.0
oracle/banking_payments 14.0.0
... and 39 more
Published Oct 23, 2019
Tracked Since Feb 18, 2026