QID 982267

QID 982267: Java (maven) Security Update for org.apache.poi:poi (GHSA-523c-xh4g-mh5m)

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks:
- Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294)
- Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295)

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-523c-xh4g-mh5m for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982267

    Software Advisories
    Advisory ID Software Component Link
    GHSA-523c-xh4g-mh5m org.apache.poi:poi URL Logo github.com/advisories/GHSA-523c-xh4g-mh5m