CVE-2016-5000

medium Apache
CVSS v3 Base Score
5.5
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.3%
Exploitation probability in 30 days
Top 44% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
High
Integrity
None
Availability
None
Published: August 5, 2016 (3570 days ago)
Last Modified: May 6, 2026
Vendor: Apache
Source: NVD

Description

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CWE

CWE-611

Affected Products

apache poi

References