peter bassill · operator
$ cve CVE-2019-0228 JSON

CVE-2019-0228

9.8
CRITICAL · CVSS 3.1 · EPSS 9.5% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS9.45% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploitnone known
Published2019-04-17
Last modified2026-06-17

Affected (14)

VendorProduct
apachejames
apachepdfbox
fedoraprojectfedora
oraclebanking corporate lending process management
oraclebanking credit facilities process management
oraclebanking supply chain finance
oraclebanking trade finance process management
oraclebanking virtual account management
oraclecommunications messaging server
oraclecommunications session report manager
oraclehyperion financial reporting
oraclepeoplesoft enterprise peopletools
oracleretail xstore point of service
oraclewebcenter sites

References

→ the Explorer  ·  watch your stack  ·  NVD