← Back

CVE-2019-0228

nvd nist
Published: Apr 17, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

Affected (32)

2 products
Pdfbox
James
1 product
Fedora
11 products
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.0.14
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 3.3.0
Version 3.4.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 29
Version 30
Configuration D
27 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 14.2
Version 14.3
Version 14.5
Oracle
Version 14.2
Version 14.3
Version 14.5
Oracle
Version 14.2
Version 14.3
Version 14.5
Oracle
Version 14.2
Version 14.3
Version 14.5
Oracle
Version 14.2
Version 14.3.0
Version 14.5
Oracle
Version 8.1
Version 8.1
From 8.0.0.0 to 8.2.4.0
Oracle
Version 11.1.2.4
Version 11.2.6.0
Oracle
Version 8.58
Version 8.59
Oracle
Version 16.0.6
Version 17.0
Version 18.0.3
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0

References (24)

Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.