CVE-2022-38745

CVE-2022-38745: Apache OpenOffice: Empty entry in Java class path

Vendor Apache Software Foundation
Product Apache OpenOffice
Weakness CWE-94 · Code injection
Published March 24, 2023
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.

Key dates

Disclosure timeline

March 24, 2023 CVE published
February 13, 2025 Record updated