- CVE ID
- CVE-2019-12415
- CVE Description
- In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
- Published
- Oct 31, 2019
- CVSS Score & Severity
5.5Medium
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS Score
- 0.033%
- KEV Status
Not in KEV Catalog: No known exploits
- Source
- National Vulnerability Database