Input validation error in Apache POI - CVE-2025-31672

 

Input validation error in Apache POI - CVE-2025-31672

Published: July 4, 2025


Vulnerability identifier: #VU112257
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31672
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to manipulate file parsing behavior.

The vulnerability stems from the way Apache POI handles zip entries in OOXML format files. When duplicate file names (including paths) exist within the zip structure, different products may select different zip entries with the same name, leading to inconsistent data interpretation. A remote attacker can manipulate file parsing behavior through specially crafted OOXML files containing ZIP entries with duplicate file names. This manipulation can result in inconsistent data processing across different systems, potentially leading to security issues and data integrity concerns.


Affected software

Apache POI
Netcool Operations Insight
SAP BusinessObjects Business Intelligence suite
IBM Sterling B2B Integrator
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
Oracle Middleware Common Libraries and Tools
Oracle Enterprise Command Center Framework
IBM SPSS Modeler
Operations Analytics - Log Analysis
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Oracle Business Intelligence Enterprise Edition
Oracle Financial Services Analytical Applications Infrastructure
IBM Business Automation Manager Open Editions
Cloudera Observability with IBM
Engineering Lifecycle Management - Jazz Foundation
IBM Engineering Requirements Management DOORS Next
watsonx.data
IBM Sterling File Gateway
PeopleSoft Enterprise PeopleTools
Oracle Fusion Middleware
Operational Decision Manager
JD Edwards EnterpriseOne Tools
Oracle Agile PLM Framework
Oracle Application Development Framework (ADF)
Oracle Business Process Management Suite
IBM Cognos Controller

How to mitigate CVE-2025-31672

Install updates from vendor's website.

Apache POI - update to 5.4.0
Operations Analytics - Log Analysis - update to 1.3.8.4
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2.1
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.1.3
IBM Sterling B2B Integrator - addressed in versions 6.1.2.7.1, 6.2.0.5, 6.2.1.1
IBM Sterling File Gateway - addressed in versions 6.1.2.7.1, 6.2.0.5, 6.2.1.1
IBM Tivoli Netcool Impact - update to 7.1.0.37
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.18
IBM Business Automation Manager Open Editions - update to 9.2.1
Cloudera Observability with IBM - update to 3.6.2
Engineering Lifecycle Management - Jazz Foundation - addressed in versions 7.0.3 iFix019, 7.1.0 iFix006
IBM Engineering Requirements Management DOORS Next - update to 7.1.0 ifix 004
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 54, 8.11.1 Interim fix 53, 8.12.0.1 Interim fix 37, 9.0.0.1 Interim fix 22, 9.5.0.1 Interim fix 5
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1

External References

Related Security Bulletins