CVE-2025-31672 is an Improper Input Validation vulnerability in Apache POI, affecting versions prior to 5.4.0, including products like Apache Active IQ Unified Manager and NetApp POI. It arises from the parsing of OOXML files (e.g., .xlsx, .docx) where malicious users can embed duplicate zip entry names, leading to inconsistent data interpretation across different products. Rated with a CVSS score of 5.3 (Medium), the vulnerability has a network attack vector and low attack complexity, requiring no user interaction or privileges. Its potential impact is limited to data integrity (I:L), as different products might read varying data from the malformed file, but does not affect confidentiality or availability. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available. Community discussion and media coverage are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.4.0CPE matchmatch criteria | cpe:2.3:a:apache:poi:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP Device Manager Vulnerability Update (5.0.16)
Mar 9, 2026Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing
Apr 9, 2025org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
Apr 9, 2025