Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5000

Опубликовано: 22 июл. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 7.1

Описание

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6poiNot affected
Red Hat Enterprise Virtualization 3jasperreports-server-proNot affected
Red Hat JBoss BRMS 5poiNot affected
Red Hat JBoss BRMS 6poiNot affected
Red Hat JBoss Data Virtualization 6poiNot affected
Red Hat JBoss Fuse Service Works 6poiNot affected
Red Hat JBoss Portal 6poiNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1359663poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example

7.5 High

CVSS3

7.1 High

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 10 лет назад

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 5.5
nvd
около 10 лет назад

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 5.5
debian
около 10 лет назад

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers ...

CVSS3: 5.5
github
больше 4 лет назад

Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability

7.5 High

CVSS3

7.1 High

CVSS2