ZeroHour

CVE-2022-38745

CVSS 3.1
7.8 high
EPSS
<1%p57
Published
()
Modified
Description

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.

Vendors
apache
Products
openoffice
Weakness
CWE-94, CWE-427, CWE-1188
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.