CVE-2019-0228
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Affected (32)
Products: Apache: Pdfbox, James · Fedoraproject: Fedora · Oracle: Banking Corporate Lending Process Management, Banking Credit Facilities Process Management, Banking Supply Chain Finance, Banking Trade Finance Process Management, Banking Virtual Account Management, Communications Messaging Server, Communications Session Report Manager, Hyperion Financial Reporting, Peoplesoft Enterprise Peopletools, Retail Xstore Point Of Service, Webcenter Sites
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 29 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.2 | |
| Version 14.2 | |
| Version 14.2 | |
| Version 14.2 | |
| Version 14.2 | |
| Version 8.1 | |
| From 8.0.0.0 to 8.2.4.0 | |
| Version 11.1.2.4 | |
| Version 8.58 | |
| Version 16.0.6 | |
| Version 12.2.1.3.0 |
References (24)
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.