CRITICAL · 9.8

CVE-2019-0228

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

Vulnerability Description

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ApachePdfbox2.0.14
ApacheJames3.3.0
FedoraprojectFedora29
OracleBanking Corporate Lending Process Management14.2
OracleBanking Credit Facilities Process Management14.2
OracleBanking Supply Chain Finance14.2
OracleBanking Trade Finance Process Management14.2
OracleBanking Virtual Account Management14.2
OracleCommunications Messaging Server8.1
OracleCommunications Session Report Manager>= 8.0.0.0, <= 8.2.4.0
OracleHyperion Financial Reporting11.1.2.4
OraclePeoplesoft Enterprise Peopletools8.58
OracleRetail Xstore Point Of Service16.0.6
OracleWebcenter Sites12.2.1.3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-0228?

CVE-2019-0228 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

How severe is CVE-2019-0228?

CVE-2019-0228 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-0228?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Pdfbox, Apache James, Fedoraproject Fedora, Oracle Banking Corporate Lending Process Management, Oracle Banking Credit Facilities Process Management.