Security Advisory

CVE-2017-5644

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-03-24 14:00:00
Last updated 2024-08-05 15:11:47
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.