CVE-2022-26336

MEDIUM

Apache POI <5.2.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.

References (2)

Core 2

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 12.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-770 CWE-20
Status published
Products (3)
apache/poi < 5.2.1
netapp/active_iq_unified_manager (3 CPE variants)
org.apache.poi/poi-scratchpad 3.8-beta1 - 5.2.1Maven
Published Mar 04, 2022
Tracked Since Feb 18, 2026