CVE-2019-12415
published 2019-10-23CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an…
PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.99%
58.6th percentile
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | poi | <= 4.1.0 | — |
| debian | libapache-poi-java | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | banking_enterprise_originations | — | — |
| oracle | banking_enterprise_originations | — | — |
| oracle | banking_enterprise_product_manufacturing | — | — |
| oracle | banking_enterprise_product_manufacturing | — | — |
| oracle | banking_payments | — | — |
| oracle | banking_payments | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | big_data_discovery | — | — |
| oracle | communications_diameter_signaling_router_idih | — | — |
| oracle | endeca_information_discovery_studio | — | — |
| oracle | enterprise_manager_base_platform | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Runtime Engine (Apache POI) — CVE-2019-12415
vendor_oracle·2025-01-15·CVSS 5.5
CVE-2019-12415 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Runtime Engine (Apache POI) — CVE-2019-12415
Oracle Oracle Fusion Middleware Risk Matrix: Runtime Engine (Apache POI) vulnerability
CVE: CVE-2019-12415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache POI) — CVE-2019-12415
vendor_oracle·2023-04-15·CVSS 5.5
CVE-2019-12415 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache POI) — CVE-2019-12415
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache POI) vulnerability
CVE: CVE-2019-12415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Supply Chain Risk Matrix: Installation (Apache POI) — CVE-2019-12415
vendor_oracle·2023-01-15·CVSS 5.5
CVE-2019-12415 [MEDIUM] Oracle Oracle Supply Chain Risk Matrix: Installation (Apache POI) — CVE-2019-12415
Oracle Oracle Supply Chain Risk Matrix: Installation (Apache POI) vulnerability
CVE: CVE-2019-12415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Framework Administrator IBFA (Apache POI) — CVE-2019-12415
vendor_oracle·2022-10-15·CVSS 5.5
CVE-2019-12415 [MEDIUM] Oracle Oracle Insurance Applications Risk Matrix: Framework Administrator IBFA (Apache POI) — CVE-2019-12415
Oracle Oracle Insurance Applications Risk Matrix: Framework Administrator IBFA (Apache POI) vulnerability
CVE: CVE-2019-12415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache POI) — CVE-2019-12415
vendor_oracle·2021-10-15·CVSS 5.5
CVE-2019-12415 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache POI) — CVE-2019-12415
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache POI) vulnerability
CVE: CVE-2019-12415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: OAM (Apache POI) — CVE-2019-12415
vendor_oracle·2021-07-15·CVSS 5.5
CVE-2019-12415 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: OAM (Apache POI) — CVE-2019-12415
Oracle Oracle Fusion Middleware Risk Matrix: OAM (Apache POI) vulnerability
CVE: CVE-2019-12415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Hyperion Risk Matrix: Common Security (Apache POI) — CVE-2019-12415
vendor_oracle·2021-01-15·CVSS 5.5
CVE-2019-12415 [MEDIUM] Oracle Oracle Hyperion Risk Matrix: Common Security (Apache POI) — CVE-2019-12415
Oracle Oracle Hyperion Risk Matrix: Common Security (Apache POI) vulnerability
CVE: CVE-2019-12415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Risk Matrix: IDIH (Apache POI) — CVE-2019-12415
vendor_oracle·2020-10-15·CVSS 5.5
CVE-2019-12415 [MEDIUM] Oracle Oracle Communications Risk Matrix: IDIH (Apache POI) — CVE-2019-12415
Oracle Oracle Communications Risk Matrix: IDIH (Apache POI) vulnerability
CVE: CVE-2019-12415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Mgmt (Apache POI) — CVE-2019-12415
vendor_oracle·2020-07-15·CVSS 5.5
CVE-2019-12415 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Mgmt (Apache POI) — CVE-2019-12415
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Mgmt (Apache POI) vulnerability
CVE: CVE-2019-12415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Office Open document processor (Apache POI) — CVE-2019-12415
vendor_oracle·2020-04-15·CVSS 5.5
CVE-2019-12415 [MEDIUM] Oracle Oracle Construction and Engineering Risk Matrix: Office Open document processor (Apache POI) — CVE-2019-12415
Oracle Oracle Construction and Engineering Risk Matrix: Office Open document processor (Apache POI) vulnerability
CVE: CVE-2019-12415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2020 (APR 2020)
Red Hat
poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem
vendor_redhat·2020-02-13·CVSS 5.5
CVE-2019-12415 [MEDIUM] CWE-611 poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem
poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Mitigation: The vulnerability is in the XSSFExportToXml util; avoid usage of this tool to mitigate the vulnerability.
Package: poi (Red Hat BPM Suite 6) - Out of support scope
Package: poi (Red Hat Decision Manager 7) - Fix deferred
Package: poi (Red Hat JBoss BRMS 5) - Out of support scope
Package: poi (Red Hat JBoss Data Virtualization 6) - Out of support scope
Package: poi (Red Hat JBoss Fuse 6) -
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache POI) — CVE-2019-12415
vendor_oracle·2020-01-15·CVSS 5.5
CVE-2019-12415 [MEDIUM] Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache POI) — CVE-2019-12415
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache POI) vulnerability
CVE: CVE-2019-12415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2020 (JAN 2020)
Debian
CVE-2019-12415: libapache-poi-java - In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-p...
vendor_debian·2019·CVSS 5.5
CVE-2019-12415 [MEDIUM] CVE-2019-12415: libapache-poi-java - In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-p...
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
Improper Restriction of XML External Entity Reference in Apache POI
osv·2022-05-24
CVE-2019-12415 [MEDIUM] Improper Restriction of XML External Entity Reference in Apache POI
Improper Restriction of XML External Entity Reference in Apache POI
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
GHSA
Improper Restriction of XML External Entity Reference in Apache POI
ghsa·2022-05-24
CVE-2019-12415 [MEDIUM] CWE-611 Improper Restriction of XML External Entity Reference in Apache POI
Improper Restriction of XML External Entity Reference in Apache POI
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
OSV
CVE-2019-12415: In Apache POI up to 4
osv·2019-10-23·CVSS 5.5
CVE-2019-12415 [MEDIUM] CVE-2019-12415: In Apache POI up to 4
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-12415 apache-poi: poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem [fedora-all]
bugzilla·2020-02-13·CVSS 5.5
CVE-2019-12415 [MEDIUM] CVE-2019-12415 apache-poi: poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem [fedora-all]
CVE-2019-12415 apache-poi: poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg c
Bugzilla
CVE-2019-12415 poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem
bugzilla·2020-02-13·CVSS 5.5
CVE-2019-12415 [MEDIUM] CVE-2019-12415 poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem
CVE-2019-12415 poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem
In Apache POI up to 4.1.0, when converting user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Upstream Advisory:
https://lists.apache.org/thread.html/13a54b6a03369cfb418a699180ffb83bd727320b6ddfec198b9b728e@%3Cannounce.apache.org%3E
Discussion:
Created apache-poi tracking bugs for this issue:
Affects: fedora-all [bug 1802532]
---
Mitigation:
The vulnerability is in the XSSFExportToXml util; avoid usage of this tool to mitigate the vulnerability.
---
This issue has been addressed in the following products:
https://lists.apache.org/thread.html/13a54b6a03369cfb418a699180ffb83bd727320b6ddfec198b9b728e%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/2ac0327748de0c2b3c1c012481b79936797c711724e0b7da83cf564c%40%3Cuser.tika.apache.org%3Ehttps://lists.apache.org/thread.html/895164e03a3c327449069e2fd6ced0367561878b3ae6a8ec740c2007%40%3Cuser.tika.apache.org%3Ehttps://lists.apache.org/thread.html/d88b8823867033514d7ec05d66f88c70dc207604d3dcbd44fd88464c%40%3Cuser.tika.apache.org%3Ehttps://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://lists.apache.org/thread.html/13a54b6a03369cfb418a699180ffb83bd727320b6ddfec198b9b728e%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/2ac0327748de0c2b3c1c012481b79936797c711724e0b7da83cf564c%40%3Cuser.tika.apache.org%3Ehttps://lists.apache.org/thread.html/895164e03a3c327449069e2fd6ced0367561878b3ae6a8ec740c2007%40%3Cuser.tika.apache.org%3Ehttps://lists.apache.org/thread.html/d88b8823867033514d7ec05d66f88c70dc207604d3dcbd44fd88464c%40%3Cuser.tika.apache.org%3Ehttps://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2019-10-23
Published