MEDIUM · 5.5

CVE-2019-12415

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local files...

Vulnerability Description

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ApachePoi<= 4.1.0
OracleApplication Testing Suite12.5.0.3
OracleBanking Enterprise Originations2.7.0
OracleBanking Enterprise Product Manufacturing2.7.0
OracleBanking Payments14.0.0
OracleBanking Platform2.4.0
OracleBig Data Discovery1.6
OracleCommunications Diameter Signaling Router Idih\
OracleEndeca Information Discovery Studio3.2.0
OracleEnterprise Manager Base Platform12.1.0.5
OracleEnterprise Repository12.1.3.0.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6, <= 8.0.9
OracleFinancial Services Market Risk Measurement And Management8.0.6
OracleFlexcube Private Banking12.0.0
OracleHyperion Infrastructure Technology11.1.2.4
OracleInstantis Enterprisetrack17.1
OracleInsurance Policy Administration J2Ee11.0.2
OracleInsurance Rules Palette10.2.0
OracleJdeveloper12.2.1.4.0
OraclePeoplesoft Enterprise Peopletools8.57

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-12415?

CVE-2019-12415 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local files...

How severe is CVE-2019-12415?

CVE-2019-12415 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-12415?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Poi, Oracle Application Testing Suite, Oracle Banking Enterprise Originations, Oracle Banking Enterprise Product Manufacturing, Oracle Banking Payments.