CVE-2016-5000
published 2016-08-05CVE-2016-5000: The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity…
PriorityP336medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
4.15%
89.8th percentile
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | poi | <= 3.13 | — |
| debian | libapache-poi-java | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_cisco10.0CRITICAL
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability
ghsa·2022-05-13
CVE-2016-5000 [MEDIUM] CWE-611 Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability
Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
OSV
Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability
osv·2022-05-13
CVE-2016-5000 [MEDIUM] Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability
Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
OSV
CVE-2016-5000: The XLSX2CSV example in Apache POI before 3
osv·2016-08-05·CVSS 5.5
CVE-2016-5000 [MEDIUM] CVE-2016-5000: The XLSX2CSV example in Apache POI before 3
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Cisco
Cisco ASR 5000 Software ipsecmgr Process IKE Packet Parsing Denial of Service Vulnerability
vendor_cisco·2017-01-18·CVSS 5.3
CVE-2016-9216 [MEDIUM] CWE-399 Cisco ASR 5000 Software ipsecmgr Process IKE Packet Parsing Denial of Service Vulnerability
Cisco ASR 5000 Software ipsecmgr Process IKE Packet Parsing Denial of Service Vulnerability
A vulnerability in the ipsecmgr process of Cisco ASR 5000 Software could allow an unauthenticated, remote attacker to cause the ipsecmgr process to reload.
The vulnerability is due to a logical error while parsing IKE packets. An attacker could exploit this vulnerability by submitting malformed IKE packets to the targeted system.
There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170118-asr
Cisco
Cisco ASR 5000 Series IKEv2 Denial of Service Vulnerability
vendor_cisco·2016-12-07·CVSS 5.0
CVE-2016-9203 [MEDIUM] CWE-119 Cisco ASR 5000 Series IKEv2 Denial of Service Vulnerability
Cisco ASR 5000 Series IKEv2 Denial of Service Vulnerability
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco ASR 5000 Series Software could allow an unauthenticated, remote attacker to cause a reload of the ipsecmgr process.
The vulnerability is due to a race condition in the IKEv2 negotiation logic. An attacker could exploit this vulnerability by sending crafted IKEv2 packets during a negotiation. An exploit could allow the attacker to cause a crash of the ipsecmgr process, which will restart on its own. Only the connection being negotiated will need to re-establish.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisc
Cisco
Cisco ASR 5000 Series IPv6 Packet Processing Denial of Service Vulnerability
vendor_cisco·2016-12-07·CVSS 5.0
CVE-2016-6467 [MEDIUM] CWE-399 Cisco ASR 5000 Series IPv6 Packet Processing Denial of Service Vulnerability
Cisco ASR 5000 Series IPv6 Packet Processing Denial of Service Vulnerability
A vulnerability in IPv6 packet fragment reassembly of StarOS for Cisco Aggregation Services Router (ASR) 5000 Series Switch could allow an unauthenticated, remote attacker to cause an unexpected reload of the Network Processing Unit (NPU) process.
The vulnerability is due to lack of proper input validation of the IPv6 fragment lengths. An attacker could exploit this vulnerability by sending a crafted IPv6 fragment chain to the targeted device. An exploit could allow the attacker to cause a denial of service (DoS) condition if the NPU process unexpectedly reloads. The DoS condition could temporarily impact user traffic.
There are no workarounds that address this vulnerability.
This advisory is available at the
Cisco
Cisco ASR 5000 Series ipsecmgr Service Denial of Service Vulnerability
vendor_cisco·2016-11-16·CVSS 5.0
CVE-2016-6466 [MEDIUM] CWE-399 Cisco ASR 5000 Series ipsecmgr Service Denial of Service Vulnerability
Cisco ASR 5000 Series ipsecmgr Service Denial of Service Vulnerability
A vulnerability in the IPsec component of StarOS for Cisco ASR 5000 Series routers could allow an unauthenticated, remote attacker to terminate all active IPsec VPN tunnels and prevent new tunnels from establishing, resulting in a denial of service (DoS) condition.
The vulnerability is due to improper processing of Internet Key Exchange (IKE) messages. An attacker could exploit this vulnerability by sending crafted IKE messages toward the router. An exploit could allow the attacker to cause a reload of the ipsecmgr service. A reload of the ipsecmgr service might result in all IPsec VPN tunnels being terminated and new tunnels being unable to establish until the service has restarted, resulting in a denial of service (
Red Hat
poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example
vendor_redhat·2016-07-22·CVSS 5.5
CVE-2016-5000 [MEDIUM] CWE-611 poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example
poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Package: jasperreports-server-pro (Red Hat Enterprise Virtualization 3) - Not affected
Package: poi (Red Hat JBoss BPMS 6.3.0) - Not affected
Package: poi (Red Hat JBoss BRMS 5.3.1) - Not affected
Package: poi (Red Hat JBoss BRMS 6.3.0) - Not affected
Package: poi (Red Hat JBoss Data Virtualization 6.2.4) - Not affected
Package: poi (Red Hat JBoss Fuse Service Works 6) - Not affected
Package: poi (Red Hat JBoss Portal Platform 6.2.0) - Not affected
Cisco
Vulnerability in Objective Systems ASN1C Compiler Affecting Cisco Products
vendor_cisco·2016-07-22·CVSS 10.0
CVE-2016-5080 [CRITICAL] CWE-119 Vulnerability in Objective Systems ASN1C Compiler Affecting Cisco Products
Vulnerability in Objective Systems ASN1C Compiler Affecting Cisco Products
A vulnerability in the ASN1C compiler by Objective Systems affects Cisco ASR 5000 devices running StarOS and Cisco Virtualized Packet Core (VPC) systems. The vulnerability could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition or potentially execute arbitrary code.
The vulnerability is due to unsafe code generation by the ASN1C compiler when creating ASN.1 translation functions that are subsequently included within affected Cisco products. An attacker could exploit this vulnerability by submitting a malicious Abstract Syntax Notation One (ASN.1) encoded message designed to trigger the issue to an affected function.
US-CERT has released Vulnerability Note VU#790839 to documen
Cisco
Cisco ASR 5000 Series SNMP Community String Disclosure Vulnerability
vendor_cisco·2016-07-13·CVSS 4.0
CVE-2016-1452 [MEDIUM] CWE-200 Cisco ASR 5000 Series SNMP Community String Disclosure Vulnerability
Cisco ASR 5000 Series SNMP Community String Disclosure Vulnerability
A vulnerability in SNMP configuration management in the Cisco ASR 5000 Series could allow an unauthenticated, remote attacker to read and modify the device configuration using an SNMP read-write community string.
The vulnerability occurs because the configured SNMP community string is not confidential. An attacker could perform an SNMP query to the affected device to view the SNMP community string. An exploit could allow the attacker to read and modify the device configuration using the disclosed SNMP read-write community string.
Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: https://s
Cisco
Cisco ASR 5000 Series Packet Data Network Gateway Denial of Service Vulnerability
vendor_cisco·2016-06-21·CVSS 5.0
CVE-2016-1436 [MEDIUM] CWE-119 Cisco ASR 5000 Series Packet Data Network Gateway Denial of Service Vulnerability
Cisco ASR 5000 Series Packet Data Network Gateway Denial of Service Vulnerability
A vulnerability in the implementation of General Packet Radio Switching Tunneling Protocol Version 1 (GTPv1) in Cisco ASR 5000 Series Packet Data Network Gateways could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to an unexpected restart of the Session Manager process for the device.
The vulnerability is due to improper input validation of GTPv1 packet headers. An attacker could exploit this vulnerability by sending a crafted GTPv1 packet to a targeted device. A successful exploit could allow the attacker to cause the Session Manager process for the device to restart unexpectedly, resulting in a DoS condition.
Cisco has released software updates that address t
Cisco
Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
vendor_cisco·2016-05-13·CVSS 5.0
CVE-2016-1399 [MEDIUM] CWE-399 Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
A vulnerability in the packet processing microcode of Cisco Industrial Ethernet 4000 Series Switches and Cisco Industrial Ethernet 5000 Series Switches could allow an unauthenticated, remote attacker to corrupt packets enqueued on the device for further processing.
The vulnerability is due to improper processing of some ICMP IPv4 packets. An attacker could exploit this vulnerability by sending ICMP IPv4 packets to an affected device. A successful exploit could allow an attacker to corrupt the packet enqueued immediately after the packet sent. This may impact control traffic to the device itself (Address Resolution Protocol (ARP) traffic) or traffic transiting the device.
Cisco has
Cisco
Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
vendor_cisco·2016-02-18·CVSS 7.1
CVE-2016-1335 [HIGH] CWE-264 Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
A privilege escalation vulnerability in the SSH subsystem in Cisco ASR 5000 Series devices running StarOS could allow an authenticated, remote attacker to elevate privileges. The attacker would need to have a valid and configured SSH authorized key and access to the same device from which the privileged administrator connects.
The vulnerability is due to an error that occurs when multiple users are configured to use SSH keys as the authentication mechanism. Administrative accounts configured in this manner are tied to a single remote device. A successful attack could allow a lower-privileged user to authenticate as a higher-privileged administrator if all constraints can be met.
Cisco has released software upd
Debian
CVE-2016-5000: libapache-poi-java - The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read a...
vendor_debian·2016·CVSS 5.5
CVE-2016-5000 [MEDIUM] CVE-2016-5000: libapache-poi-java - The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read a...
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Cisco
Cisco ASR 5000 Series IPv6 Packet Processing Denial of Service Vulnerability
vendor_cisco
CVE-2016-6467 Cisco ASR 5000 Series IPv6 Packet Processing Denial of Service Vulnerability
CVE-2016-6467: Cisco ASR 5000 Series IPv6 Packet Processing Denial of Service Vulnerability
A vulnerability in IPv6 packet fragment reassembly of StarOS for Cisco Aggregation Services Router (ASR) 5000 Series Switch could allow an unauthenticated, remote attacker to cause an unexpected reload of the Network Processing Unit (NPU) process. The vulnerability is due to lack of proper input validation of the IPv6 fragment lengths. An attacker could exploit this vulnerability by sending a crafted IPv6 fragment chain to the targeted device. An exploit could allow the attacker to cause a denial of service (DoS) condition if the NPU process unexpectedly reloads. The DoS condition could temporarily impact user traffic. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCva84552
Cisco
Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
vendor_cisco
CVE-2016-1335 Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
CVE-2016-1335: Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
A privilege escalation vulnerability in the SSH subsystem in Cisco ASR 5000 Series devices running StarOS could allow an authenticated, remote attacker to elevate privileges. The attacker would need to have a valid and configured SSH authorized key and access to the same device from which the privileged administrator connects. The vulnerability is due to an error that occurs when multiple users are configured to use SSH keys as the authentication mechanism. Administrative accounts configured in this manner are tied to a single remote device. A successful attack could allow a lower-privileged user to authenticate as a higher-privileged administrator if all constraints can be met. Cisco has released
Cisco
Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
vendor_cisco
CVE-2016-1399 Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
CVE-2016-1399: Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
A vulnerability in the packet processing microcode of Cisco Industrial Ethernet 4000 Series Switches and Cisco Industrial Ethernet 5000 Series Switches could allow an unauthenticated, remote attacker to corrupt packets enqueued on the device for further processing. The vulnerability is due to improper processing of some ICMP IPv4 packets. An attacker could exploit this vulnerability by sending ICMP IPv4 packets to an affected device. A successful exploit could allow an attacker to corrupt the packet enqueued immediately after the packet sent. This may impact control traffic to the device itself (Address Resolution Protocol (ARP) traffic) or traffic transiting the device
Cisco
Vulnerability in Objective Systems ASN1C Compiler Affecting Cisco Products
vendor_cisco
CVE-2016-5080 Vulnerability in Objective Systems ASN1C Compiler Affecting Cisco Products
CVE-2016-5080: Vulnerability in Objective Systems ASN1C Compiler Affecting Cisco Products
A vulnerability in the ASN1C compiler by Objective Systems affects Cisco ASR 5000 devices running StarOS and Cisco Virtualized Packet Core (VPC) systems. The vulnerability could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition or potentially execute arbitrary code. The vulnerability is due to unsafe code generation by the ASN1C compiler when creating ASN.1 translation functions that are subsequently included within affected Cisco products. An attacker could exploit this vulnerability by submitting a malicious Abstract Syntax Notation One (ASN.1) encoded message designed to trigger the issue to an affected function. US-CERT has released Vulnerability Note VU#79083
Cisco
Cisco ASR 5000 Series Packet Data Network Gateway Denial of Service Vulnerability
vendor_cisco
CVE-2016-1436 Cisco ASR 5000 Series Packet Data Network Gateway Denial of Service Vulnerability
CVE-2016-1436: Cisco ASR 5000 Series Packet Data Network Gateway Denial of Service Vulnerability
A vulnerability in the implementation of General Packet Radio Switching Tunneling Protocol Version 1 (GTPv1) in Cisco ASR 5000 Series Packet Data Network Gateways could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to an unexpected restart of the Session Manager process for the device. The vulnerability is due to improper input validation of GTPv1 packet headers. An attacker could exploit this vulnerability by sending a crafted GTPv1 packet to a targeted device. A successful exploit could allow the attacker to cause the Session Manager process for the device to restart unexpectedly, resulting in a DoS condition. Cisco has released software updates th
Cisco
Cisco ASR 5000 Series SNMP Community String Disclosure Vulnerability
vendor_cisco
CVE-2016-1452 Cisco ASR 5000 Series SNMP Community String Disclosure Vulnerability
CVE-2016-1452: Cisco ASR 5000 Series SNMP Community String Disclosure Vulnerability
A vulnerability in SNMP configuration management in the Cisco ASR 5000 Series could allow an unauthenticated, remote attacker to read and modify the device configuration using an SNMP read-write community string. The vulnerability occurs because the configured SNMP community string is not confidential. An attacker could perform an SNMP query to the affected device to view the SNMP community string. An exploit could allow the attacker to read and modify the device configuration using the disclosed SNMP read-write community string. Cisco has released software updates that address this vulnerability.
CWE: CWE-200, CWE-200
Bug IDs: CSCuz29526
Cisco
Cisco ASR 5000 Series ipsecmgr Service Denial of Service Vulnerability
vendor_cisco
CVE-2016-6466 Cisco ASR 5000 Series ipsecmgr Service Denial of Service Vulnerability
CVE-2016-6466: Cisco ASR 5000 Series ipsecmgr Service Denial of Service Vulnerability
A vulnerability in the IPsec component of StarOS for Cisco ASR 5000 Series routers could allow an unauthenticated, remote attacker to terminate all active IPsec VPN tunnels and prevent new tunnels from establishing, resulting in a denial of service (DoS) condition. The vulnerability is due to improper processing of Internet Key Exchange (IKE) messages. An attacker could exploit this vulnerability by sending crafted IKE messages toward the router. An exploit could allow the attacker to cause a reload of the ipsecmgr service. A reload of the ipsecmgr service might result in all IPsec VPN tunnels being terminated and new tunnels being unable to establish until the service has restarted, resulting in a denial
Cisco
Cisco ASR 5000 Software ipsecmgr Process IKE Packet Parsing Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2016-9216 Cisco ASR 5000 Software ipsecmgr Process IKE Packet Parsing Denial of Service Vulnerability
CVE-2016-9216: Cisco ASR 5000 Software ipsecmgr Process IKE Packet Parsing Denial of Service Vulnerability
A vulnerability in the ipsecmgr process of Cisco ASR 5000 Software could allow an unauthenticated, remote attacker to cause the ipsecmgr process to reload. The vulnerability is due to a logical error while parsing IKE packets. An attacker could exploit this vulnerability by submitting malformed IKE packets to the targeted system. There are no
CVSS: 3.0
CWE: CWE-399, CWE-399
Bug IDs: CSCuy06917, CSCuy45036, CSCuy59525
Cisco
Cisco ASR 5000 Series IKEv2 Denial of Service Vulnerability
vendor_cisco
CVE-2016-9203 Cisco ASR 5000 Series IKEv2 Denial of Service Vulnerability
CVE-2016-9203: Cisco ASR 5000 Series IKEv2 Denial of Service Vulnerability
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco ASR 5000 Series Software could allow an unauthenticated, remote attacker to cause a reload of the ipsecmgr process. The vulnerability is due to a race condition in the IKEv2 negotiation logic. An attacker could exploit this vulnerability by sending crafted IKEv2 packets during a negotiation. An exploit could allow the attacker to cause a crash of the ipsecmgr process, which will restart on its own. Only the connection being negotiated will need to re-establish. There are no
CWE: CWE-119, CWE-119
Bug IDs: CSCvb38398
No detection rules found.
Bugzilla
CVE-2016-5000 apache-poi: poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example [fedora-all]
bugzilla·2016-07-25·CVSS 5.5
CVE-2016-5000 [MEDIUM] CVE-2016-5000 apache-poi: poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example [fedora-all]
CVE-2016-5000 apache-poi: poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2016-5000 poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example
bugzilla·2016-07-25·CVSS 5.5
CVE-2016-5000 [MEDIUM] CVE-2016-5000 poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example
CVE-2016-5000 poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example
Apache POI's XLSX2CSV example uses Java's XML components to parse OpenXML files. Applications and users that use XLSX2CSV and accept such files from end-users are vulnerable to XML External Entity (XXE) attacks, which allow remote attackers to bypass security restrictions and read arbitrary files via a crafted OpenXML document that provides an XML external entity declaration in conjunction with an entity reference.
Affected versions: POI 3.5-3.13
Public via:
http://seclists.org/bugtraq/2016/Jul/106
Discussion:
Created apache-poi tracking bugs for this issue:
Affects: fedora-all [bug 1359664]
http://www-01.ibm.com/support/docview.wss?uid=swg21996759http://www.securityfocus.com/archive/1/538981/100/0/threadedhttp://www.securityfocus.com/bid/92100http://www.securitytracker.com/id/1037741https://lists.apache.org/list.html?user%40poi.apache.orghttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21996759http://www.securityfocus.com/archive/1/538981/100/0/threadedhttp://www.securityfocus.com/bid/92100http://www.securitytracker.com/id/1037741https://lists.apache.org/list.html?user%40poi.apache.orghttps://www.oracle.com/security-alerts/cpuoct2020.html
2016-08-05
Published