Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3529

Опубликовано: 18 авг. 2014
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

It was found that Apache POI would resolve entities in OOXML documents. A remote attacker able to supply OOXML documents that are parsed by Apache POI could use this flaw to read files accessible to the user running the application server, and potentially perform more advanced XML External Entity (XXE) attacks.

Отчет

Red Hat Product Security has determined that CVE-2014-3529 is not exploitable by default in JBoss Portal Platform as provided by Red Hat. This flaw would only be exploitable if the Apache POI library provided by JBoss Portal Platform were used by a custom application to process user-supplied XML documents.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6apache-poiAffected
Red Hat Enterprise Virtualization 3jasperreports-server-proAffected
Red Hat JBoss BRMS 5apache-poiWill not fix
Red Hat JBoss BRMS 6apache-poiAffected
Red Hat JBoss Portal 5apache-poiWill not fix
Red Hat JBoss BPMS 6.0FixedRHSA-2014:139913.10.2014
Red Hat JBoss BRMS 6.0FixedRHSA-2014:140013.10.2014
Red Hat JBoss Data Virtualization 6.0apache-poiFixedRHSA-2014:139813.10.2014
Red Hat JBoss Fuse Service Works 6.0apache-poiFixedRHSA-2014:137009.10.2014
Red Hat JBoss Portal 6.2apache-poiFixedRHSA-2015:100914.05.2015

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1138135apache-poi: XML eXternal Entity (XXE) flaw

EPSS

Процентиль: 89%
0.04546
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

nvd
больше 11 лет назад

The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

debian
больше 11 лет назад

The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers ...

github
больше 3 лет назад

Improper Restriction of XML External Entity Reference in Apache POI

EPSS

Процентиль: 89%
0.04546
Низкий

5 Medium

CVSS2