XML Entity Expansion in Apache POI - CVE-2017-5644
Published: February 13, 2024
Vulnerability identifier: #VU86355
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5644
CWE-ID: CWE-776
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service attack.
The vulnerability exists due to insufficient validation of user-supplied XML input. A local user can pass a specially crafted OOXML file to the affected application and perform a denial of service attack.
Affected software
Apache POI
IBM Intelligent Operations Center
Atlas eDiscovery Process Management
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite - Manage Component
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Dell Support Assist Enterprise
IBM Cognos Controller
IBM Intelligent Operations Center
Atlas eDiscovery Process Management
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite - Manage Component
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Dell Support Assist Enterprise
IBM Cognos Controller
How to mitigate CVE-2017-5644
Install updates from vendor's website.
Apache POI - update to 3.15
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Intelligent Operations Center - update to 5.2.4
Atlas eDiscovery Process Management - update to 6.0.3.9.7
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.26, 8.7.20, 9.0.13
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF028, 23.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Intelligent Operations Center - update to 5.2.4
Atlas eDiscovery Process Management - update to 6.0.3.9.7
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.26, 8.7.20, 9.0.13
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF028, 23.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM Intelligent Operations Center (IOC)
- Multiple vulnerabilities in Atlas eDiscovery Process Management
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM Maximo Application Suite - Manage Component
- Multiple vulnerabilities in IBM Controller