VYPR
Medium severity5.5NVD Advisory· Published Mar 24, 2017· Updated May 13, 2026

CVE-2017-5644

CVE-2017-5644

Description

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.poi:poiMaven
< 3.153.15

Affected products

2
  • cpe:2.3:a:apache:poi:*:*:*:*:*:*:*:*
    Range: <=3.14
  • Apache Software Foundation/Apache POIv5
    Range: before 3.15

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.