CVE-2017-12626
published 2018-01-29CVE-2017-12626: Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
10.06%
95.1th percentile
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | poi | < 3.17 | 3.17 |
| apache | tika | — | — |
| apache_software_foundation | apache_poi | < 3.17 | 3.17 |
| debian | libapache-poi-java | < libapache-poi-java 3.17-1 (bookworm) | libapache-poi-java 3.17-1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Sales Audit Maintenance (Apache POI) — CVE-2017-12626
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2017-12626 [HIGH] Oracle Oracle Retail Applications Risk Matrix: Sales Audit Maintenance (Apache POI) — CVE-2017-12626
Oracle Oracle Retail Applications Risk Matrix: Sales Audit Maintenance (Apache POI) vulnerability
CVE: CVE-2017-12626
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache POI) — CVE-2017-12626
vendor_oracle·2021-01-15·CVSS 7.5
CVE-2017-12626 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: General (Apache POI) — CVE-2017-12626
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache POI) vulnerability
CVE: CVE-2017-12626
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Architecture (Apache POI) — CVE-2017-12626
vendor_oracle·2020-07-15·CVSS 7.5
CVE-2017-12626 [HIGH] Oracle Oracle Insurance Applications Risk Matrix: Architecture (Apache POI) — CVE-2017-12626
Oracle Oracle Insurance Applications Risk Matrix: Architecture (Apache POI) vulnerability
CVE: CVE-2017-12626
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Apache POI) — CVE-2017-12626
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2017-12626 [HIGH] Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Apache POI) — CVE-2017-12626
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Apache POI) vulnerability
CVE: CVE-2017-12626
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache POI) — CVE-2017-12626
vendor_oracle·2020-01-15·CVSS 7.5
CVE-2017-12626 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache POI) — CVE-2017-12626
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache POI) vulnerability
CVE: CVE-2017-12626
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Red Hat
poi: Parsing of multiple file types can cause a denial of service via infinite loop or out of memory exception
vendor_redhat·2018-01-26·CVSS 7.5
CVE-2017-12626 [HIGH] CWE-835 poi: Parsing of multiple file types can cause a denial of service via infinite loop or out of memory exception
poi: Parsing of multiple file types can cause a denial of service via infinite loop or out of memory exception
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
Package: poi (Red Hat BPM Suite 6) - Affected
Package: apache-poi (Red Hat Enterprise Linux 8) - Not affected
Package: poi (Red Hat JBoss BRMS 5) - Not affected
Package: poi (Red Hat JBoss BRMS 6) - Affected
Package: poi (Red Hat JBoss Data Virtualization 6) - Will not fix
Package: poi (Red Hat JBoss Fuse Service Works 6) - Will not fix
Package: poi (Red Hat JBoss Portal 6) - Will not fix
Debian
CVE-2017-12626: libapache-poi-java - Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service...
vendor_debian·2017·CVSS 7.5
CVE-2017-12626 [HIGH] CVE-2017-12626: libapache-poi-java - Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service...
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
Scope: local
bookworm: resolved (fixed in 3.17-1)
bullseye: resolved (fixed in 3.17-1)
forky: resolved (fixed in 3.17-1)
sid: resolved (fixed in 3.17-1)
trixie: resolved (fixed in 3.17-1)
Apache
Apache tika: CVE-2017-12626
vendor_apache·CVSS 7.5
CVE-2017-12626 [HIGH] Apache tika: CVE-2017-12626
Apache tika: CVE-2017-12626
Apache POI - Infinite loops in WMF, EMF, MSG and macros; OOMs in DOC, PPT and XLS Tim Allison, Luís Filipe Nassif and Jerome Lacoste ?-1.17
VulDB
Apache POI up to 3.16 resource management (RHSA-2018:1322 / Nessus ID 106717)
vuldb·2026-05-29·CVSS 7.5
CVE-2017-12626 [HIGH] Apache POI up to 3.16 resource management (RHSA-2018:1322 / Nessus ID 106717)
A vulnerability categorized as problematic has been discovered in Apache POI up to 3.16. The affected element is an unknown function. Executing a manipulation can lead to improper resource management.
The identification of this vulnerability is CVE-2017-12626. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
Denial of Service in Apache POI
ghsa·2021-01-14
CVE-2017-12626 [HIGH] CWE-835 Denial of Service in Apache POI
Denial of Service in Apache POI
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks:
- Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294)
- Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295)
OSV
Denial of Service in Apache POI
osv·2021-01-14
CVE-2017-12626 [HIGH] Denial of Service in Apache POI
Denial of Service in Apache POI
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks:
- Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294)
- Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295)
OSV
CVE-2017-12626: Apache POI in versions prior to release 3
osv·2018-01-29·CVSS 7.5
CVE-2017-12626 [HIGH] CVE-2017-12626: Apache POI in versions prior to release 3
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12626 poi: Parsing of multiple file types can cause a denial of service via infinite loop or out of memory exception
bugzilla·2018-01-30·CVSS 7.5
CVE-2017-12626 [HIGH] CVE-2017-12626 poi: Parsing of multiple file types can cause a denial of service via infinite loop or out of memory exception
CVE-2017-12626 poi: Parsing of multiple file types can cause a denial of service via infinite loop or out of memory exception
Apache POI versions prior to release 3.17 are vulnerable to Denial of Service (DoS) attacks caused by multiple bugs in parsing specially crafted files.
Parsing of WMF, EMF, MSG files and macros can lead to infinite loops, while parsing DOC, PPT and XLS files can cause out of memory exceptions.
External References:
https://nvd.nist.gov/vuln/detail/CVE-2017-12626
https://lists.apache.org/thread.html/453d9af5dbabaccd9afb58d27279a9dbfe8e35f4e5ea1645ddd6960b@%3Cdev.poi.apache.org%3E
Discussion:
Created apache-poi tracking bugs for this issue:
Affects: fedora-all [bug 1539990]
---
According to the upstream announcement, this CVE covers 4 issues tracked in the foll
Bugzilla
CVE-2017-12626 apache-poi: poi: Parsing of multiple file types can cause a denial of service via infinite loop or out of memory exception [fedora-all]
bugzilla·2018-01-30·CVSS 7.5
CVE-2017-12626 [HIGH] CVE-2017-12626 apache-poi: poi: Parsing of multiple file types can cause a denial of service via infinite loop or out of memory exception [fedora-all]
CVE-2017-12626 apache-poi: poi: Parsing of multiple file types can cause a denial of service via infinite loop or out of memory exception [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fed
http://www.securityfocus.com/bid/102879https://access.redhat.com/errata/RHSA-2018:1322https://lists.apache.org/thread.html/453d9af5dbabaccd9afb58d27279a9dbfe8e35f4e5ea1645ddd6960b%40%3Cdev.poi.apache.org%3Ehttps://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://www.securityfocus.com/bid/102879https://access.redhat.com/errata/RHSA-2018:1322https://lists.apache.org/thread.html/453d9af5dbabaccd9afb58d27279a9dbfe8e35f4e5ea1645ddd6960b%40%3Cdev.poi.apache.org%3Ehttps://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2018-01-29
Published