The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
https://exchange.xforce.ibmcloud.com/vulnerabilities/95770
http://www.securityfocus.com/bid/78018
http://www.securityfocus.com/bid/69647
http://www.apache.org/dist/poi/release/RELEASE-NOTES.txt
http://www-01.ibm.com/support/docview.wss?uid=swg21996759
http://secunia.com/advisories/61766
http://secunia.com/advisories/60419
http://secunia.com/advisories/59943
http://rhn.redhat.com/errata/RHSA-2014-1400.html
http://rhn.redhat.com/errata/RHSA-2014-1399.html
http://rhn.redhat.com/errata/RHSA-2014-1398.html