cbcvebase.
CVE-2019-12415
published 2019-10-23

CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an…

PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.99%
58.9th percentile
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

Affected

65 ranges· showing 25
VendorProductVersion rangeFixed in
apachepoi<= 4.1.0
debianlibapache-poi-java
oracleapplication_testing_suite
oracleapplication_testing_suite
oracleapplication_testing_suite
oracleapplication_testing_suite
oraclebanking_enterprise_originations
oraclebanking_enterprise_originations
oraclebanking_enterprise_product_manufacturing
oraclebanking_enterprise_product_manufacturing
oraclebanking_payments
oraclebanking_payments
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebig_data_discovery
oraclecommunications_diameter_signaling_router_idih
oracleendeca_information_discovery_studio
oracleenterprise_manager_base_platform

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.