Vulnerability Description
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Poi | < 5.2.1 |
| Netapp | Active Iq Unified Manager | - |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/sprg0kq986pc2271dc3v2oxb1f9qx09jMailing ListVendor Advisory
- https://security.netapp.com/advisory/ntap-20221028-0006/Third Party Advisory
- https://lists.apache.org/thread/sprg0kq986pc2271dc3v2oxb1f9qx09jMailing ListVendor Advisory
- https://security.netapp.com/advisory/ntap-20221028-0006/Third Party Advisory
FAQ
What is CVE-2022-26336?
CVE-2022-26336 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchan...
How severe is CVE-2022-26336?
CVE-2022-26336 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-26336?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Poi, Netapp Active Iq Unified Manager.