CVE-2017-5644

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:poi:*:*:*:*:*:*:*:*

Information

Published : 2017-03-24 07:59

Updated : 2020-10-20 15:15


NVD link : CVE-2017-5644

Mitre link : CVE-2017-5644


JSON object : View

CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

Advertisement

dedicated server usa

Products Affected

apache

  • poi