ZeroHour

CVE-2019-0228

CVSS 3.1
9.8 critical
EPSS
9%p95
Published
()
Modified
Description

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

Vendors
apachefedoraprojectoracle
Products
pdfbox, james, fedora, banking corporate lending process management, banking credit facilities process management, banking supply chain finance, banking trade finance process management, banking virtual account management, communications messaging server, communications session report manager, hyperion financial reporting, peoplesoft enterprise peopletools
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.