Vulnerability Name:

CVE-2016-5000 (CCN-115530)

Assigned:2016-07-22
Published:2016-07-22
Updated:2020-10-20
Summary:The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-611
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2016-5000

Source: CCN
Type: BugTraq Mailing List, Fri, 22 Jul 2016 19:18:13 +0000 (UTC)
[CVE-2016-5000] XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example

Source: CONFIRM
Type: UNKNOWN
http://www-01.ibm.com/support/docview.wss?uid=swg21996759

Source: CCN
Type: IBM Security Bulletin 1989525 (Maximo Asset Management)
Multiple vulnerabilities in Apache POI affect Asset and Service Management

Source: CCN
Type: IBM Security Bulletin 1991850 (WebSphere Dashboard Framework)
IBM WebSphere Dashboard Framework is affected by a security vulnerability in Apache POI(CVE-2016-5000)

Source: CCN
Type: IBM Security Bulletin 1991851 (Web Experience Factory)
IBM Web Experience Factory is affected by a security vulnerability in Apache POI(CVE-2016-5000)

Source: CCN
Type: IBM Security Bulletin 1991969 (PredictiveInsight)
Multiple vulnerabilities in Apache POI affect IBM PredictiveInsight

Source: CCN
Type: IBM Security Bulletin 1994719 (Security QRadar SIEM)
Apache POI as used in IBM QRadar SIEM is vulnerable to variousCVEs.

Source: CCN
Type: IBM Security Bulletin 1996759 (InfoSphere Information Server)
Vulnerabilities in Apache POI affects IBM InfoSphere Information Server

Source: CCN
Type: IBM Security Bulletin 1997296 (Forms Experience Builder)
IBM Forms Experience Builder could be susceptible to Apache POI Vulnerabilities

Source: CCN
Type: IBM Security Bulletin 1997727 (OpenPages GRC Platform)
IBM OpenPages GRC Platform has addressed multiple Apache POI vulnerabilities (CVE-2017-5644, CVE-2016-5000, CVE-2014-3574)

Source: CCN
Type: Oracle CPUJan2017
Oracle Critical Patch Update Advisory - January 2017

Source: BUGTRAQ
Type: UNKNOWN
20160722 [CVE-2016-5000] XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example

Source: BID
Type: UNKNOWN
92100

Source: CCN
Type: BID-92100
Apache POI CVE-2016-5000 XML External Entity Injection Vulnerability

Source: SECTRACK
Type: UNKNOWN
1037741

Source: XF
Type: UNKNOWN
apache-poi-cve20165000-info-disc(115530)

Source: MLIST
Type: Mailing List
[users] 20160722 [CVE-2016-5000] XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example

Source: CCN
Type: Apache Web site
POI

Source: CCN
Type: IBM Security Bulletin 876670 (Campaign)
Apache POI Vulnerability Affects IBM Campaign (CVE-2016-5000)

Source: CCN
Type: IBM Security Bulletin 1992041 (eDiscovery Manager)
pen Source Apache Poi Vulnerability in IBM eDiscovery Manager

Source: MISC
Type: UNKNOWN
https://www.oracle.com/security-alerts/cpuoct2020.html

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-5000

Vulnerable Configuration:Configuration 1:
  • cpe:/a:apache:poi:*:*:*:*:*:*:*:* (Version <= 3.13)

  • Configuration CCN 1:
  • cpe:/a:ibm:maximo_asset_management:7.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:maximo_asset_management:7.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:infosphere_information_server:8.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:infosphere_information_server:9.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_dashboard_framework:7.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:web_experience_factory:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:campaign:9.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:maximo_asset_management:7.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:ediscovery_manager:2.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:forms_experience_builder:8.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:web_experience_factory:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:web_experience_factory:8.5.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:infosphere_information_server:11.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:forms_experience_builder:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:maximo_asset_management:7.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:predictiveinsight:8.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:predictiveinsight:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:openpages_grc_platform:7.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:infosphere_information_server:11.5:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:retail_order_broker_cloud_service:4.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:campaign:9.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:retail_order_broker_cloud_service:5.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:retail_order_broker_cloud_service:5.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:retail_order_broker_cloud_service:15.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:retail_order_broker_cloud_service:16.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:openpages_grc_platform:7.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:openpages_grc_platform:7.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:campaign:10.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:campaign:11.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.ubuntu.bionic:def:201650000000000
    V
    CVE-2016-5000 on Ubuntu 18.04 LTS (bionic) - negligible.
    2016-08-05
    oval:com.ubuntu.artful:def:20165000000
    V
    CVE-2016-5000 on Ubuntu 17.10 (artful) - medium.
    2016-08-05
    oval:com.ubuntu.trusty:def:20165000000
    V
    CVE-2016-5000 on Ubuntu 14.04 LTS (trusty) - negligible.
    2016-08-05
    oval:com.ubuntu.xenial:def:201650000000000
    V
    CVE-2016-5000 on Ubuntu 16.04 LTS (xenial) - negligible.
    2016-08-05
    oval:com.ubuntu.bionic:def:20165000000
    V
    CVE-2016-5000 on Ubuntu 18.04 LTS (bionic) - negligible.
    2016-08-05
    oval:com.ubuntu.xenial:def:20165000000
    V
    CVE-2016-5000 on Ubuntu 16.04 LTS (xenial) - negligible.
    2016-08-05
    oval:com.ubuntu.disco:def:201650000000000
    V
    CVE-2016-5000 on Ubuntu 19.04 (disco) - negligible.
    2016-08-05
    oval:com.ubuntu.cosmic:def:20165000000
    V
    CVE-2016-5000 on Ubuntu 18.10 (cosmic) - negligible.
    2016-08-05
    oval:com.ubuntu.cosmic:def:201650000000000
    V
    CVE-2016-5000 on Ubuntu 18.10 (cosmic) - negligible.
    2016-08-05
    oval:com.ubuntu.precise:def:20165000000
    V
    CVE-2016-5000 on Ubuntu 12.04 LTS (precise) - medium.
    2016-08-05
    BACK
    apache poi *
    ibm maximo asset management 7.1
    ibm maximo asset management 7.5
    ibm infosphere information server 8.7
    ibm infosphere information server 9.1
    ibm qradar security information and event manager 7.1
    ibm websphere dashboard framework 7.0.1
    ibm web experience factory 8.0
    ibm campaign 9.1
    ibm qradar security information and event manager 7.2
    ibm maximo asset management 7.1.1
    ibm ediscovery manager 2.2.2
    ibm forms experience builder 8.5.1
    ibm web experience factory 8.5
    ibm web experience factory 8.5.0.1
    ibm infosphere information server 11.3
    ibm forms experience builder 8.5
    ibm maximo asset management 7.6
    ibm predictiveinsight 8.6
    ibm predictiveinsight 9.0
    ibm openpages grc platform 7.1
    ibm infosphere information server 11.5
    oracle retail order broker cloud service 4.1
    ibm campaign 9.1.2
    oracle retail order broker cloud service 5.1
    oracle retail order broker cloud service 5.2
    oracle retail order broker cloud service 15.0
    oracle retail order broker cloud service 16.0
    ibm openpages grc platform 7.2
    ibm openpages grc platform 7.3
    ibm campaign 10.1
    ibm campaign 11.0