imPC@ndo IT

Tracker / CVE-2019-12415

CVE-2019-12415

Medium 5.5

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

Affected products and versions

apache poi · … → 4.1.0
oracle application_testing_suite
oracle banking_enterprise_originations
oracle banking_enterprise_product_manufacturing
oracle banking_payments
oracle banking_platform
oracle big_data_discovery
oracle communications_diameter_signaling_router_idih\
oracle endeca_information_discovery_studio
oracle enterprise_manager_base_platform
oracle enterprise_repository
oracle financial_services_analytical_applications_infrastructure · 8.0.6 → 8.0.9
oracle financial_services_market_risk_measurement_and_management
oracle flexcube_private_banking
oracle hyperion_infrastructure_technology
oracle instantis_enterprisetrack
oracle insurance_policy_administration_j2ee
oracle insurance_rules_palette
oracle jdeveloper
oracle peoplesoft_enterprise_peopletools
oracle primavera_gateway
oracle primavera_unifier
oracle primavera_unifier · 17.7 → 17.12
oracle retail_clearance_optimization_engine
oracle retail_order_broker
oracle retail_predictive_application_server
oracle webcenter_portal
oracle webcenter_sites

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References