CVE-2022-38745

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*

History

13 Feb 2025, 15:15

Type Values Removed Values Added
References (MISC) https://www.openoffice.org/security/cves/CVE-2022-38745.html - Vendor Advisory () https://www.openoffice.org/security/cves/CVE-2022-38745.html - Vendor Advisory
References (MISC) https://lists.apache.org/thread/q3noq7m681kvtb29m28x74q8cnwnzzo0 - Mailing List, Vendor Advisory () https://lists.apache.org/thread/q3noq7m681kvtb29m28x74q8cnwnzzo0 - Mailing List, Vendor Advisory
CWE CWE-94
CWE-1188
CWE-427

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory. Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.

Information

Published : 2023-03-24 16:15

Updated : 2025-02-13 15:15


NVD link : CVE-2022-38745

Mitre link : CVE-2022-38745


JSON object : View

Products Affected

apache

  • openoffice
CWE

No CWE.