Lucene search

K
redhatRedHatRHSA-2014:1399
HistoryOct 13, 2014 - 4:38 p.m.

(RHSA-2014:1399) Moderate: Apache POI security update

2014-10-1316:38:20
access.redhat.com
10

0.012 Low

EPSS

Percentile

85.0%

Apache POI is a library providing Java API for working with OOXML document
files.

It was found that Apache POI would resolve entities in OOXML documents.
A remote attacker able to supply OOXML documents that are parsed by Apache
POI could use this flaw to read files accessible to the user running the
application server, and potentially perform more advanced XML External
Entity (XXE) attacks. (CVE-2014-3529)

It was found that Apache POI would expand an unlimited number of entities
in OOXML documents. A remote attacker able to supply OOXML documents that
are parsed by Apache POI could use this flaw to trigger a denial of service
attack via excessive CPU and memory consumption. (CVE-2014-3574)

All users of Red Hat JBoss BPM Suite 6.0.3 as provided from the Red Hat
Customer Portal are advised to apply this security update.