// For flags

CVE-2019-12415

poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

En Apache POI versiones hasta 4.1.0, cuando se utiliza la herramienta XSSFExportToXml para convertir documentos de Microsoft Excel proporcionados por el usuario, un documento especialmente diseƱado puede permitir a un atacante leer archivos del sistema de archivos local o de los recursos de la red interna por medio de un Procesamiento de Entidad Externa XML (XXE).

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-05-28 CVE Reserved
  • 2019-10-23 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-10-16 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (15)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Poi
Search vendor "Apache" for product "Poi"
<= 4.1.0
Search vendor "Apache" for product "Poi" and version " <= 4.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
12.5.0.3
Search vendor "Oracle" for product "Application Testing Suite" and version "12.5.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
13.1.0.1
Search vendor "Oracle" for product "Application Testing Suite" and version "13.1.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
13.2.0.1
Search vendor "Oracle" for product "Application Testing Suite" and version "13.2.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
13.3.0.1
Search vendor "Oracle" for product "Application Testing Suite" and version "13.3.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Enterprise Originations
Search vendor "Oracle" for product "Banking Enterprise Originations"
2.7.0
Search vendor "Oracle" for product "Banking Enterprise Originations" and version "2.7.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Enterprise Originations
Search vendor "Oracle" for product "Banking Enterprise Originations"
2.8.0
Search vendor "Oracle" for product "Banking Enterprise Originations" and version "2.8.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Enterprise Product Manufacturing
Search vendor "Oracle" for product "Banking Enterprise Product Manufacturing"
2.7.0
Search vendor "Oracle" for product "Banking Enterprise Product Manufacturing" and version "2.7.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Enterprise Product Manufacturing
Search vendor "Oracle" for product "Banking Enterprise Product Manufacturing"
2.8.0
Search vendor "Oracle" for product "Banking Enterprise Product Manufacturing" and version "2.8.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Payments
Search vendor "Oracle" for product "Banking Payments"
14.0.0
Search vendor "Oracle" for product "Banking Payments" and version "14.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Payments
Search vendor "Oracle" for product "Banking Payments"
14.1.0
Search vendor "Oracle" for product "Banking Payments" and version "14.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.4.0
Search vendor "Oracle" for product "Banking Platform" and version "2.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.4.1
Search vendor "Oracle" for product "Banking Platform" and version "2.4.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.5.0
Search vendor "Oracle" for product "Banking Platform" and version "2.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.6.0
Search vendor "Oracle" for product "Banking Platform" and version "2.6.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.6.1
Search vendor "Oracle" for product "Banking Platform" and version "2.6.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.6.2
Search vendor "Oracle" for product "Banking Platform" and version "2.6.2"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.7.0
Search vendor "Oracle" for product "Banking Platform" and version "2.7.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.7.1
Search vendor "Oracle" for product "Banking Platform" and version "2.7.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.9.0
Search vendor "Oracle" for product "Banking Platform" and version "2.9.0"
-
Affected
Oracle
Search vendor "Oracle"
Big Data Discovery
Search vendor "Oracle" for product "Big Data Discovery"
1.6
Search vendor "Oracle" for product "Big Data Discovery" and version "1.6"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router Idih:
Search vendor "Oracle" for product "Communications Diameter Signaling Router Idih:"
8.0.0
Search vendor "Oracle" for product "Communications Diameter Signaling Router Idih:" and version "8.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router Idih:
Search vendor "Oracle" for product "Communications Diameter Signaling Router Idih:"
8.2.2
Search vendor "Oracle" for product "Communications Diameter Signaling Router Idih:" and version "8.2.2"
-
Affected
Oracle
Search vendor "Oracle"
Endeca Information Discovery Studio
Search vendor "Oracle" for product "Endeca Information Discovery Studio"
3.2.0
Search vendor "Oracle" for product "Endeca Information Discovery Studio" and version "3.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
12.1.0.5
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "12.1.0.5"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
13.3.0.0
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.3.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
13.4.0.0
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.4.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Repository
Search vendor "Oracle" for product "Enterprise Repository"
12.1.3.0.0
Search vendor "Oracle" for product "Enterprise Repository" and version "12.1.3.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Financial Services Analytical Applications Infrastructure
Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure"
>= 8.0.6 <= 8.0.9
Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" and version " >= 8.0.6 <= 8.0.9"
-
Affected
Oracle
Search vendor "Oracle"
Financial Services Market Risk Measurement And Management
Search vendor "Oracle" for product "Financial Services Market Risk Measurement And Management"
8.0.6
Search vendor "Oracle" for product "Financial Services Market Risk Measurement And Management" and version "8.0.6"
-
Affected
Oracle
Search vendor "Oracle"
Financial Services Market Risk Measurement And Management
Search vendor "Oracle" for product "Financial Services Market Risk Measurement And Management"
8.0.8
Search vendor "Oracle" for product "Financial Services Market Risk Measurement And Management" and version "8.0.8"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Private Banking
Search vendor "Oracle" for product "Flexcube Private Banking"
12.0.0
Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Private Banking
Search vendor "Oracle" for product "Flexcube Private Banking"
12.1.0
Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Hyperion Infrastructure Technology
Search vendor "Oracle" for product "Hyperion Infrastructure Technology"
11.1.2.4
Search vendor "Oracle" for product "Hyperion Infrastructure Technology" and version "11.1.2.4"
-
Affected
Oracle
Search vendor "Oracle"
Instantis Enterprisetrack
Search vendor "Oracle" for product "Instantis Enterprisetrack"
17.1
Search vendor "Oracle" for product "Instantis Enterprisetrack" and version "17.1"
-
Affected
Oracle
Search vendor "Oracle"
Instantis Enterprisetrack
Search vendor "Oracle" for product "Instantis Enterprisetrack"
17.2
Search vendor "Oracle" for product "Instantis Enterprisetrack" and version "17.2"
-
Affected
Oracle
Search vendor "Oracle"
Instantis Enterprisetrack
Search vendor "Oracle" for product "Instantis Enterprisetrack"
17.3
Search vendor "Oracle" for product "Instantis Enterprisetrack" and version "17.3"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Policy Administration J2ee
Search vendor "Oracle" for product "Insurance Policy Administration J2ee"
11.0.2
Search vendor "Oracle" for product "Insurance Policy Administration J2ee" and version "11.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Policy Administration J2ee
Search vendor "Oracle" for product "Insurance Policy Administration J2ee"
11.1.0
Search vendor "Oracle" for product "Insurance Policy Administration J2ee" and version "11.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Policy Administration J2ee
Search vendor "Oracle" for product "Insurance Policy Administration J2ee"
11.2.0
Search vendor "Oracle" for product "Insurance Policy Administration J2ee" and version "11.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
10.2.0
Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
10.2.4
Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.2.4"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
11.0.2
Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
11.1.0
Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
11.2.0
Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Jdeveloper
Search vendor "Oracle" for product "Jdeveloper"
12.2.1.4.0
Search vendor "Oracle" for product "Jdeveloper" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.57
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.57"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.58
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.58"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.59
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.59"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
17.12.6
Search vendor "Oracle" for product "Primavera Gateway" and version "17.12.6"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
18.8.8.1
Search vendor "Oracle" for product "Primavera Gateway" and version "18.8.8.1"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Unifier
Search vendor "Oracle" for product "Primavera Unifier"
>= 17.7 <= 17.12
Search vendor "Oracle" for product "Primavera Unifier" and version " >= 17.7 <= 17.12"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Unifier
Search vendor "Oracle" for product "Primavera Unifier"
16.1
Search vendor "Oracle" for product "Primavera Unifier" and version "16.1"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Unifier
Search vendor "Oracle" for product "Primavera Unifier"
16.2
Search vendor "Oracle" for product "Primavera Unifier" and version "16.2"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Unifier
Search vendor "Oracle" for product "Primavera Unifier"
18.8
Search vendor "Oracle" for product "Primavera Unifier" and version "18.8"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Unifier
Search vendor "Oracle" for product "Primavera Unifier"
19.12
Search vendor "Oracle" for product "Primavera Unifier" and version "19.12"
-
Affected
Oracle
Search vendor "Oracle"
Retail Clearance Optimization Engine
Search vendor "Oracle" for product "Retail Clearance Optimization Engine"
14.0
Search vendor "Oracle" for product "Retail Clearance Optimization Engine" and version "14.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
15.0
Search vendor "Oracle" for product "Retail Order Broker" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
16.0
Search vendor "Oracle" for product "Retail Order Broker" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
15.0.3
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
16.0.3
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.3.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.4.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Sites
Search vendor "Oracle" for product "Webcenter Sites"
12.2.1.3.0
Search vendor "Oracle" for product "Webcenter Sites" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Sites
Search vendor "Oracle" for product "Webcenter Sites"
12.2.1.4.0
Search vendor "Oracle" for product "Webcenter Sites" and version "12.2.1.4.0"
-
Affected