CVE-2019-12415: XSS
Apache POI could allow a remote attacker to obtain sensitive information, caused by an XML external entity (XXE) error when processing XML data by tool XSSFExportToXml. By sending a specially-crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.
Other sources
In Apache POI up to 4.1.0, when converting user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Upstream Advisory:
https://lists.apache.org/thread.html/13a54b6a03369cfb418a699180ffb83bd727320b6ddfec198b9b728e@%3Cannounce.apache.org%3E
— Red Hat
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-12415?
CVE-2019-12415 is a vulnerability in Apache POI that allows a remote attacker to obtain sensitive information through an XML external entity (XXE) error.
How does CVE-2019-12415 affect Apache POI?
CVE-2019-12415 affects Apache POI up to version 4.1.0.
What is the severity of CVE-2019-12415?
CVE-2019-12415 has a severity rating of medium.
How can a remote attacker exploit CVE-2019-12415?
A remote attacker can exploit CVE-2019-12415 by sending a specially-crafted document to the tool XSSFExportToXml, which can result in obtaining sensitive information.
Where can I find more information about CVE-2019-12415?
You can find more information about CVE-2019-12415 on the CVE website (https://www.cve.org/CVERecord?id=CVE-2019-12415) and NVD (https://nvd.nist.gov/vuln/detail/CVE-2019-12415).