CVE-2019-0228

CRITICAL

Apache PDFBox 2.0.14 - XML External Entity Injection via XFDF

Title source: llm
STIX 2.1

Description

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

References (12)

Core 12
Core References
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html

Scores

CVSS v3 9.8
EPSS 0.1303
EPSS Percentile 94.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (32)
apache/james 3.3.0
apache/james 3.4.0
apache/pdfbox 2.0.14
fedoraproject/fedora 29
fedoraproject/fedora 30
oracle/banking_corporate_lending_process_management 14.2
oracle/banking_corporate_lending_process_management 14.3
oracle/banking_corporate_lending_process_management 14.5
oracle/banking_credit_facilities_process_management 14.2
oracle/banking_credit_facilities_process_management 14.3
... and 22 more
Published Apr 17, 2019
Tracked Since Feb 18, 2026