5.5
CVSSv3

CVE-2019-12415

Published: 23/10/2019 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 189
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an malicious user to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache poi

oracle flexcube private banking 12.1.0

oracle primavera unifier 16.2

oracle banking platform 2.4.0

oracle enterprise manager base platform 12.1.0.5

oracle flexcube private banking 12.0.0

oracle banking platform 2.4.1

oracle enterprise repository 12.1.3.0.0

oracle banking platform 2.5.0

oracle primavera unifier 16.1

oracle insurance rules palette 10.2.0

oracle application testing suite 12.5.0.3

oracle webcenter portal 12.2.1.3.0

oracle banking payments 14.0.0

oracle webcenter sites 12.2.1.3.0

oracle banking payments 14.1.0

oracle peoplesoft enterprise peopletools 8.57

oracle application testing suite 13.1.0.1

oracle application testing suite 13.2.0.1

oracle application testing suite 13.3.0.1

oracle retail order broker 15.0

oracle retail order broker 16.0

oracle banking platform 2.6.0

oracle banking platform 2.6.1

oracle banking platform 2.6.2

oracle primavera unifier 18.8

oracle retail predictive application server 15.0.3

oracle primavera unifier

oracle financial services market risk measurement and management 8.0.6

oracle endeca information discovery studio 3.2.0

oracle instantis enterprisetrack 17.1

oracle instantis enterprisetrack 17.2

oracle instantis enterprisetrack 17.3

oracle enterprise manager base platform 13.3.0.0

oracle peoplesoft enterprise peopletools 8.58

oracle primavera unifier 19.12

oracle webcenter sites 12.2.1.4.0

oracle webcenter portal 12.2.1.4.0

oracle enterprise manager base platform 13.4.0.0

oracle hyperion infrastructure technology 11.1.2.4

oracle financial services market risk measurement and management 8.0.8

oracle jdeveloper 12.2.1.4.0

oracle banking platform 2.7.0

oracle banking platform 2.7.1

oracle banking platform 2.9.0

oracle primavera gateway 17.12.6

oracle primavera gateway 18.8.8.1

oracle big data discovery 1.6

oracle insurance rules palette 10.2.4

oracle insurance rules palette 11.0.2

oracle insurance rules palette 11.1.0

oracle insurance rules palette 11.2.0

oracle insurance policy administration j2ee 11.0.2

oracle insurance policy administration j2ee 11.1.0

oracle insurance policy administration j2ee 11.2.0

oracle banking enterprise originations 2.8.0

oracle banking enterprise originations 2.7.0

oracle banking enterprise product manufacturing 2.7.0

oracle banking enterprise product manufacturing 2.8.0

oracle peoplesoft enterprise peopletools 8.59

oracle financial services analytical applications infrastructure

oracle retail predictive application server 16.0.3

oracle communications diameter signaling router idih\\

oracle retail clearance optimization engine 14.0

Vendor Advisories

Debian Bug report logs - #943565 libapache-poi-java: CVE-2019-12415 Package: src:libapache-poi-java; Maintainer for src:libapache-poi-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 26 Oct 2019 15:06:02 UTC Severity: impo ...