XML Entity Expansion in Apache POI - CVE-2017-5644

 

XML Entity Expansion in Apache POI - CVE-2017-5644

Published: February 13, 2024


Vulnerability identifier: #VU86355
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5644
CWE-ID: CWE-776
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to insufficient validation of user-supplied XML input. A local user can pass a specially crafted OOXML file to the affected application and perform a denial of service attack.


Affected software

Apache POI
IBM Intelligent Operations Center
Atlas eDiscovery Process Management
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite - Manage Component
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Dell Support Assist Enterprise
IBM Cognos Controller

How to mitigate CVE-2017-5644

Install updates from vendor's website.

Apache POI - update to 3.15
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Intelligent Operations Center - update to 5.2.4
Atlas eDiscovery Process Management - update to 6.0.3.9.7
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.26, 8.7.20, 9.0.13
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF028, 23.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6

External References

Related Security Bulletins