← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-0228

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:9.45%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
apache pdfbox 2.0.14
apache james 3.3.0, 3.4.0
fedoraproject fedora 29, 30
oracle banking_corporate_lending_process_management 14.2, 14.3, 14.5
oracle banking_credit_facilities_process_management 14.2, 14.3, 14.5
oracle banking_supply_chain_finance 14.2, 14.3, 14.5
oracle banking_trade_finance_process_management 14.2, 14.3, 14.5
oracle banking_virtual_account_management 14.2, 14.3.0, 14.5
oracle communications_messaging_server 8.1
oracle communications_session_report_manager all
oracle hyperion_financial_reporting 11.1.2.4, 11.2.6.0
oracle peoplesoft_enterprise_peopletools 8.58, 8.59
oracle retail_xstore_point_of_service 16.0.6, 17.0, 18.0.3
oracle webcenter_sites 12.2.1.3.0, 12.2.1.4.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
9.451%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2018-11-14T00:00:00
Published2019-04-17T14:07:34
Last Updated2024-08-04T17:44:15

LINK COPIED TO CLIPBOARD