CVE-2022-26336
published 2022-03-04CVE-2022-26336: A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.52%
71.8th percentile
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | poi | < 5.2.1 | 5.2.1 |
| apache_software_foundation | poi-scratchpad | unspecified – 5.2.0 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle JD Edwards Risk Matrix: Web Runtime SEC (Apache POI) — CVE-2022-26336
vendor_oracle·2023-01-15·CVSS 5.5
CVE-2022-26336 [MEDIUM] Oracle Oracle JD Edwards Risk Matrix: Web Runtime SEC (Apache POI) — CVE-2022-26336
Oracle Oracle JD Edwards Risk Matrix: Web Runtime SEC (Apache POI) vulnerability
CVE: CVE-2022-26336
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2023 (JAN 2023)
Red Hat
poi-scratchpad: A carefully crafted TNEF file can cause an out of memory exception
vendor_redhat·2022-03-04·CVSS 5.5
CVE-2022-26336 [MEDIUM] CWE-20 poi-scratchpad: A carefully crafted TNEF file can cause an out of memory exception
poi-scratchpad: A carefully crafted TNEF file can cause an out of memory exception
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
Package: poi-scratchpad (Logging Subsystem for Red Hat OpenShift) - Fix deferred
Package: poi-scratchpad (Red Hat build of Quarkus) - Fix deferred
Package: poi-scratchpad (Red Hat Data Grid
GHSA
Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpad
ghsa·2022-03-05
CVE-2022-26336 [MEDIUM] CWE-20 Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpad
Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpad
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
OSV
Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpad
osv·2022-03-05
CVE-2022-26336 [MEDIUM] Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpad
Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpad
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
OSV
CVE-2022-26336: A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception
osv·2022-03-04·CVSS 5.5
CVE-2022-26336 [MEDIUM] CVE-2022-26336: A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-04
Published