Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5000

Опубликовано: 22 июл. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 7.1

Описание

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Virtualization 3jasperreports-server-proNot affected
Red Hat JBoss BPMS 6.3.0poiNot affected
Red Hat JBoss BRMS 5.3.1poiNot affected
Red Hat JBoss BRMS 6.3.0poiNot affected
Red Hat JBoss Data Virtualization 6.2.4poiNot affected
Red Hat JBoss Fuse Service Works 6poiNot affected
Red Hat JBoss Portal Platform 6.2.0poiNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1359663poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example

7.5 High

CVSS3

7.1 High

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 5.5
nvd
больше 9 лет назад

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 5.5
debian
больше 9 лет назад

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers ...

CVSS3: 5.5
github
больше 3 лет назад

Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability

7.5 High

CVSS3

7.1 High

CVSS2