CVE-2019-0228
—CVSS 3.1
9.8 critical
EPSS
9%p95
Published
()
Modified
Description
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
- Vendors
- apachefedoraprojectoracle
- Products
- pdfbox, james, fedora, banking corporate lending process management, banking credit facilities process management, banking supply chain finance, banking trade finance process management, banking virtual account management, communications messaging server, communications session report manager, hyperion financial reporting, peoplesoft enterprise peopletools
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.