cbcvebase.
CVE-2019-0228
published 2019-04-17

CVE-2019-0228: Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
apachejames
apachejames
apachepdfbox
apachetika
debianlibpdfbox-java
debianlibpdfbox2-java
fedoraprojectfedora
fedoraprojectfedora
oraclebanking_corporate_lending_process_management
oraclebanking_corporate_lending_process_management
oraclebanking_corporate_lending_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_supply_chain_finance
oraclebanking_supply_chain_finance
oraclebanking_supply_chain_finance
oraclebanking_trade_finance_process_management
oraclebanking_trade_finance_process_management
oraclebanking_trade_finance_process_management
oraclebanking_virtual_account_management
oraclebanking_virtual_account_management
oraclebanking_virtual_account_management
oraclecommunications_messaging_server
oraclecommunications_session_report_manager8.0.0.0 – 8.2.4.0