Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache James
APPApache3.3.03.4.0Apache Pdfbox
APPApache2.0.14Fedora Project Fedora
OSFedoraproject2930Oracle Banking Corporate Lending Process Management
APPOracle14.214.314.5Oracle Banking Credit Facilities Process Management
APPOracle14.214.314.5Oracle Banking Supply Chain Finance
APPOracle14.214.314.5Oracle Banking Trade Finance Process Management
APPOracle14.214.314.5Oracle Banking Virtual Account Management
APPOracle14.214.3.014.5Oracle Communications Messaging Server
APPOracle8.1Oracle Communications Session Report Manager
APPOracle8.0.0.0 – 8.2.4.0Oracle Hyperion Financial Reporting
APPOracle11.1.2.411.2.6.0Oracle Peoplesoft Enterprise Peopletools
APPOracle8.588.59Oracle Retail Xstore Point Of Service
APPOracle16.0.617.018.0.3Oracle Webcenter Sites
APPOracle12.2.1.3.012.2.1.4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XXE
CWE
References
Related vulnerabilities
CVE-2026-35273CRITICAL9.8⚠ KEVPL ✓same product
Pominięcie uwierzytelnienia w Oracle PeopleSoft PeopleTools (RCE/Takeover)
CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit
CVE-2024-5274CRITICAL9.6⚠ KEVPL ✓same product
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML
CVE-2024-4947CRITICAL9.6⚠ KEVPL ✓same product
Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)
CVE-2024-4671CRITICAL9.6⚠ KEVPL ✓same product
Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox