CVE-2019-0228

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
apachepdfbox
2.0.14
apachejames
3.3.0
apachejames
3.4.0
oraclebanking_corporate_lending_process_management
14.2
oraclebanking_corporate_lending_process_management
14.3
oraclebanking_corporate_lending_process_management
14.5
oraclebanking_credit_facilities_process_management
14.2
oraclebanking_credit_facilities_process_management
14.3
oraclebanking_credit_facilities_process_management
14.5
oraclebanking_supply_chain_finance
14.2
oraclebanking_supply_chain_finance
14.3
oraclebanking_supply_chain_finance
14.5
oraclebanking_trade_finance_process_management
14.2
oraclebanking_trade_finance_process_management
14.3
oraclebanking_trade_finance_process_management
14.5
oraclebanking_virtual_account_management
14.2
oraclebanking_virtual_account_management
14.3.0
oraclebanking_virtual_account_management
14.5
oraclecommunications_messaging_server
8.1
oraclecommunications_session_report_manager
8.0.0.0 ≤
𝑥
≤ 8.2.4.0
oraclehyperion_financial_reporting
11.1.2.4
oraclehyperion_financial_reporting
11.2.6.0
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepeoplesoft_enterprise_peopletools
8.59
oracleretail_xstore_point_of_service
16.0.6
oracleretail_xstore_point_of_service
17.0
oracleretail_xstore_point_of_service
18.0.3
oraclewebcenter_sites
12.2.1.3.0
oraclewebcenter_sites
12.2.1.4.0
oraclecommunications_messaging_server
8.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libpdfbox-java
bookworm
1:1.8.16-2
fixed
bullseye
1:1.8.16-2
fixed
sid
1:1.8.16-5
fixed
trixie
1:1.8.16-5
fixed
libpdfbox2-java
bullseye
2.0.23-1
fixed
bookworm
2.0.27-2
fixed
sid
2.0.29-1
fixed
trixie
2.0.29-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libpdfbox-java
cosmic
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne
libpdfbox2-java
cosmic
not-affected
bionic
not-affected
xenial
dne
trusty
dne
References