CVE Explorer
CVE-2025-64407
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links
to be loaded without prompt. Such links could also be used to transmit system information, such as environment variables or configuration settings.
In the affected versions of Apache OpenOffice, documents that used a certain URI scheme linking to external files would
load the contents of such files without prompting t
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-201","description":"CWE-201 Insertion of Sensitive Information Into Sent Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:23bc9c355548b0b7344906474aafb17f949bcf4aa70f6d719d9e767c95e908a0 · sha256:5b875c3d988e20d3… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:23bc9c355548b0b7344906474aafb17f949bcf4aa70f6d719d9e767c95e908a0 · sha256:5b875c3d988e20d3… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Apache OpenOffice","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"4.1.15","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:23bc9c355548b0b7344906474aafb17f949bcf4aa70f6d719d9e767c95e908a0 · sha256:5b875c3d988e20d3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:23bc9c355548b0b7344906474aafb17f949bcf4aa70f6d719d9e767c95e908a0 · sha256:5b875c3d988e20d3… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-201","description":"CWE-201 Insertion of Sensitive Information Into Sent Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:23bc9c355548b0b7344906474aafb17f949bcf4aa70f6d719d9e767c95e908a0 · sha256:5b875c3d988e20d3… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:23bc9c355548b0b7344906474aafb17f949bcf4aa70f6d719d9e767c95e908a0 · sha256:5b875c3d988e20d3… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/4yg1gv71f14fw4ky4ds50o6xjq49594g"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:23bc9c355548b0b7344906474aafb17f949bcf4aa70f6d719d9e767c95e908a0 · sha256:5b875c3d988e20d3… · /containers/cna/references/1
{"tags":["vendor-advisory"],"url":"https://www.openoffice.org/security/cves/CVE-2025-64407.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:23bc9c355548b0b7344906474aafb17f949bcf4aa70f6d719d9e767c95e908a0 · sha256:5b875c3d988e20d3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.