Home

Description

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links to be loaded without prompt. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue.

PUBLISHED Reserved 2025-11-02 | Published 2025-11-12 | Updated 2025-11-12 | Assigner apache

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

Any version
affected

Credits

Reginaldo Silva of ubercomp.com finder

References

www.openwall.com/lists/oss-security/2025/11/11/6

www.openoffice.org/security/cves/CVE-2025-64403.html vendor-advisory

lists.apache.org/thread/t7c6jhvdb00xtgd9vvn7h5sq9f4h5trt vendor-advisory

cve.org (CVE-2025-64403)

nvd.nist.gov (CVE-2025-64403)

Download JSON