4.3

CVE-2014-3529

The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Poi Version <= 3.10
Apache ≫ Poi Version 0.1
Apache ≫ Poi Version 0.2
Apache ≫ Poi Version 0.3
Apache ≫ Poi Version 0.4
Apache ≫ Poi Version 0.5
Apache ≫ Poi Version 0.6
Apache ≫ Poi Version 0.7
Apache ≫ Poi Version 0.10.0
Apache ≫ Poi Version 0.11.0
Apache ≫ Poi Version 0.12.0
Apache ≫ Poi Version 0.13.0
Apache ≫ Poi Version 0.14.0
Apache ≫ Poi Version 1.0.0
Apache ≫ Poi Version 1.0.1
Apache ≫ Poi Version 1.0.2
Apache ≫ Poi Version 1.1.0
Apache ≫ Poi Version 1.2.0
Apache ≫ Poi Version 1.5
Apache ≫ Poi Version 1.5.1
Apache ≫ Poi Version 1.7 Update dev
Apache ≫ Poi Version 1.8 Update dev
Apache ≫ Poi Version 1.10 Update dev
Apache ≫ Poi Version 2.0
Apache ≫ Poi Version 2.0 Update pre1
Apache ≫ Poi Version 2.0 Update pre2
Apache ≫ Poi Version 2.0 Update pre3
Apache ≫ Poi Version 2.0 Update rc1
Apache ≫ Poi Version 2.0 Update rc2
Apache ≫ Poi Version 2.5
Apache ≫ Poi Version 2.5.1
Apache ≫ Poi Version 3.0
Apache ≫ Poi Version 3.0 Update alpha1
Apache ≫ Poi Version 3.0 Update alpha2
Apache ≫ Poi Version 3.0 Update alpha3
Apache ≫ Poi Version 3.0.1
Apache ≫ Poi Version 3.0.2
Apache ≫ Poi Version 3.0.2 Update beta1
Apache ≫ Poi Version 3.0.2 Update beta2
Apache ≫ Poi Version 3.1
Apache ≫ Poi Version 3.1 Update beta1
Apache ≫ Poi Version 3.1 Update beta2
Apache ≫ Poi Version 3.2
Apache ≫ Poi Version 3.5
Apache ≫ Poi Version 3.5 Update beta1
Apache ≫ Poi Version 3.5 Update beta2
Apache ≫ Poi Version 3.5 Update beta3
Apache ≫ Poi Version 3.5 Update beta4
Apache ≫ Poi Version 3.5 Update beta5
Apache ≫ Poi Version 3.5 Update beta6
Apache ≫ Poi Version 3.6
Apache ≫ Poi Version 3.7
Apache ≫ Poi Version 3.7 Update beta1
Apache ≫ Poi Version 3.7 Update beta2
Apache ≫ Poi Version 3.7 Update beta3
Apache ≫ Poi Version 3.8
Apache ≫ Poi Version 3.8 Update beta1
Apache ≫ Poi Version 3.8 Update beta2
Apache ≫ Poi Version 3.8 Update beta3
Apache ≫ Poi Version 3.8 Update beta4
Apache ≫ Poi Version 3.8 Update beta5
Apache ≫ Poi Version 3.9
Apache ≫ Poi Version 3.10 Update beta1
Apache ≫ Poi Version 3.10 Update beta2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.26% 0.959
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www-01.ibm.com/support/docview.wss?uid=swg21996759
http://poi.apache.org/changes.html
http://rhn.redhat.com/errata/RHSA-2014-1370.html
http://rhn.redhat.com/errata/RHSA-2014-1398.html
http://rhn.redhat.com/errata/RHSA-2014-1399.html
http://rhn.redhat.com/errata/RHSA-2014-1400.html
http://secunia.com/advisories/59943
http://secunia.com/advisories/60419
http://secunia.com/advisories/61766
http://www.apache.org/dist/poi/release/RELEASE-NOTES.txt
http://www.securityfocus.com/bid/69647
http://www.securityfocus.com/bid/78018
https://exchange.xforce.ibmcloud.com/vulnerabilities/95770
https://lucene.apache.org/solr/solrnews.html#18-august-2014-recommendation-to-update-apache-poi-in-apache-solr-480-481-and-490-installations
Vendor Advisory