CVE-2014-3529
apache-poi: XML eXternal Entity (XXE) flaw
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
La configuración de OPC SAX en Apache POI anterior a 3.10.1 permite a atacantes remotos leer ficheros arbitrarios a través de un fichero OpenXML que contiene una declaración de entidad externa XML en conjunto con una referencia de entidad, relacionado con un problema de entidad externa XML (XXE).
It was found that Apache POI would resolve entities in OOXML documents. A remote attacker able to supply OOXML documents that are parsed by Apache POI could use this flaw to read files accessible to the user running the application server, and potentially perform more advanced XML External Entity (XXE) attacks.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-14 CVE Reserved
- 2014-09-04 CVE Published
- 2024-04-16 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://poi.apache.org/changes.html | X_refsource_confirm | |
http://secunia.com/advisories/59943 | Third Party Advisory | |
http://secunia.com/advisories/60419 | Third Party Advisory | |
http://secunia.com/advisories/61766 | Third Party Advisory | |
http://www-01.ibm.com/support/docview.wss?uid=swg21996759 | X_refsource_confirm | |
http://www.apache.org/dist/poi/release/RELEASE-NOTES.txt | X_refsource_confirm | |
http://www.securityfocus.com/bid/69647 | Vdb Entry | |
http://www.securityfocus.com/bid/78018 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95770 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | <= 3.10 Search vendor "Apache" for product "Poi" and version " <= 3.10" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.1 Search vendor "Apache" for product "Poi" and version "0.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.2 Search vendor "Apache" for product "Poi" and version "0.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.3 Search vendor "Apache" for product "Poi" and version "0.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.4 Search vendor "Apache" for product "Poi" and version "0.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.5 Search vendor "Apache" for product "Poi" and version "0.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.6 Search vendor "Apache" for product "Poi" and version "0.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.7 Search vendor "Apache" for product "Poi" and version "0.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.10.0 Search vendor "Apache" for product "Poi" and version "0.10.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.11.0 Search vendor "Apache" for product "Poi" and version "0.11.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.12.0 Search vendor "Apache" for product "Poi" and version "0.12.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.13.0 Search vendor "Apache" for product "Poi" and version "0.13.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.14.0 Search vendor "Apache" for product "Poi" and version "0.14.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.0.0 Search vendor "Apache" for product "Poi" and version "1.0.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.0.1 Search vendor "Apache" for product "Poi" and version "1.0.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.0.2 Search vendor "Apache" for product "Poi" and version "1.0.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.1.0 Search vendor "Apache" for product "Poi" and version "1.1.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.2.0 Search vendor "Apache" for product "Poi" and version "1.2.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.5 Search vendor "Apache" for product "Poi" and version "1.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.5.1 Search vendor "Apache" for product "Poi" and version "1.5.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.7 Search vendor "Apache" for product "Poi" and version "1.7" | dev |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.8 Search vendor "Apache" for product "Poi" and version "1.8" | dev |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.10 Search vendor "Apache" for product "Poi" and version "1.10" | dev |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | pre1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | pre2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | pre3 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | rc1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | rc2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.5 Search vendor "Apache" for product "Poi" and version "2.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.5.1 Search vendor "Apache" for product "Poi" and version "2.5.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0 Search vendor "Apache" for product "Poi" and version "3.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0 Search vendor "Apache" for product "Poi" and version "3.0" | alpha1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0 Search vendor "Apache" for product "Poi" and version "3.0" | alpha2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0 Search vendor "Apache" for product "Poi" and version "3.0" | alpha3 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0.1 Search vendor "Apache" for product "Poi" and version "3.0.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0.2 Search vendor "Apache" for product "Poi" and version "3.0.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0.2 Search vendor "Apache" for product "Poi" and version "3.0.2" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0.2 Search vendor "Apache" for product "Poi" and version "3.0.2" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.1 Search vendor "Apache" for product "Poi" and version "3.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.1 Search vendor "Apache" for product "Poi" and version "3.1" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.1 Search vendor "Apache" for product "Poi" and version "3.1" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.2 Search vendor "Apache" for product "Poi" and version "3.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta3 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta4 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta5 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta6 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.6 Search vendor "Apache" for product "Poi" and version "3.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.7 Search vendor "Apache" for product "Poi" and version "3.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.7 Search vendor "Apache" for product "Poi" and version "3.7" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.7 Search vendor "Apache" for product "Poi" and version "3.7" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.7 Search vendor "Apache" for product "Poi" and version "3.7" | beta3 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.8 Search vendor "Apache" for product "Poi" and version "3.8" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.8 Search vendor "Apache" for product "Poi" and version "3.8" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.8 Search vendor "Apache" for product "Poi" and version "3.8" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.8 Search vendor "Apache" for product "Poi" and version "3.8" | beta3 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.8 Search vendor "Apache" for product "Poi" and version "3.8" | beta4 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.8 Search vendor "Apache" for product "Poi" and version "3.8" | beta5 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.9 Search vendor "Apache" for product "Poi" and version "3.9" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.10 Search vendor "Apache" for product "Poi" and version "3.10" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.10 Search vendor "Apache" for product "Poi" and version "3.10" | beta2 |
Affected
|