---
cve: "CVE-2017-12626"
severity: "HIGH"
cvss: 7.5
epss: "10.1%"
vendor: "Apache Software Foundation"
kev: false
exploited: false
published: "2018-01-29 17:29:00"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-14T21:30:26+02:00"
---

# CVE-2017-12626

> 7.5 HIGH

## Beschreibung

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- ab700dc2ae3a880f66a10075cbf1a502da928afb (Commit)

## Referenzen

- <https://access.redhat.com/errata/RHSA-2018:1322>
- <https://lists.apache.org/thread.html/453d9af5dbabaccd9afb58d27279a9dbfe8e35f4e5ea1645ddd6960b%40%3Cdev.poi.apache.org%3E>
- <http://www.securityfocus.com/bid/102879>
- <https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E>
- <https://www.oracle.com/security-alerts/cpuapr2020.html>
- <https://www.oracle.com/security-alerts/cpujul2020.html>
- <https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html>
- <https://www.oracle.com/security-alerts/cpujan2020.html>
- <https://www.oracle.com/security-alerts/cpuoct2020.html>
- <https://www.oracle.com/security-alerts/cpujan2021.html>
- <https://www.oracle.com/security-alerts/cpuApr2021.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2017-12626) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
