Tracker / CVE-2019-0228
CVE-2019-0228
Critical 9.8
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Affected products and versions
| apache | james |
|---|---|
| apache | pdfbox |
| fedoraproject | fedora |
| oracle | banking_corporate_lending_process_management |
| oracle | banking_credit_facilities_process_management |
| oracle | banking_supply_chain_finance |
| oracle | banking_trade_finance_process_management |
| oracle | banking_virtual_account_management |
| oracle | communications_messaging_server |
| oracle | communications_session_report_manager · 8.0.0.0 → 8.2.4.0 |
| oracle | hyperion_financial_reporting |
| oracle | peoplesoft_enterprise_peopletools |
| oracle | retail_xstore_point_of_service |
| oracle | webcenter_sites |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.