← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-12415

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

No Active Exploit Signals
CVSS Base Score
5.5
MEDIUM
EPSS Probability:0.99%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
apache poi all
oracle application_testing_suite 12.5.0.3, 13.1.0.1, 13.2.0.1, 13.3.0.1
oracle banking_enterprise_originations 2.7.0, 2.8.0
oracle banking_enterprise_product_manufacturing 2.7.0, 2.8.0
oracle banking_payments 14.0.0, 14.1.0
oracle banking_platform 2.4.0, 2.4.1, 2.5.0, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, 2.9.0
oracle big_data_discovery 1.6
oracle communications_diameter_signaling_router_idih\ all
oracle endeca_information_discovery_studio 3.2.0
oracle enterprise_manager_base_platform 12.1.0.5, 13.3.0.0, 13.4.0.0
oracle enterprise_repository 12.1.3.0.0
oracle financial_services_analytical_applications_infrastructure all
oracle financial_services_market_risk_measurement_and_management 8.0.6, 8.0.8
oracle flexcube_private_banking 12.0.0, 12.1.0
oracle hyperion_infrastructure_technology 11.1.2.4
oracle instantis_enterprisetrack 17.1, 17.2, 17.3
oracle insurance_policy_administration_j2ee 11.0.2, 11.1.0, 11.2.0
oracle insurance_rules_palette 10.2.0, 10.2.4, 11.0.2, 11.1.0, 11.2.0
oracle jdeveloper 12.2.1.4.0
oracle peoplesoft_enterprise_peopletools 8.57, 8.58, 8.59
oracle primavera_gateway 17.12.6, 18.8.8.1
oracle primavera_unifier 16.1, 16.2, 18.8, 19.12
oracle retail_clearance_optimization_engine 14.0
oracle retail_order_broker 15.0, 16.0
oracle retail_predictive_application_server 15.0.3, 16.0.3
oracle webcenter_portal 12.2.1.3.0, 12.2.1.4.0
oracle webcenter_sites 12.2.1.3.0, 12.2.1.4.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.990%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2019-05-28T00:00:00
Published2019-10-23T19:27:20
Last Updated2024-08-04T23:17:40

LINK COPIED TO CLIPBOARD