CRITICAL🇵🇱 Wersja polska

CVE-2019-0228

CVSS 9.8v3.1pub. 2019-04-17upd. 2024-11-21

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache James

    APP
    Apache
    3.3.03.4.0
  • Apache Pdfbox

    APP
    Apache
    2.0.14
  • Fedora Project Fedora

    OS
    Fedoraproject
    2930
  • Oracle Banking Corporate Lending Process Management

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Credit Facilities Process Management

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Supply Chain Finance

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Trade Finance Process Management

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Virtual Account Management

    APP
    Oracle
    14.214.3.014.5
  • Oracle Communications Messaging Server

    APP
    Oracle
    8.1
  • Oracle Communications Session Report Manager

    APP
    Oracle
    8.0.0.0 – 8.2.4.0
  • Oracle Hyperion Financial Reporting

    APP
    Oracle
    11.1.2.411.2.6.0
  • Oracle Peoplesoft Enterprise Peopletools

    APP
    Oracle
    8.588.59
  • Oracle Retail Xstore Point Of Service

    APP
    Oracle
    16.0.617.018.0.3
  • Oracle Webcenter Sites

    APP
    Oracle
    12.2.1.3.012.2.1.4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XXE
CWE
References

Related vulnerabilities

CVE-2026-35273CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelnienia w Oracle PeopleSoft PeopleTools (RCE/Takeover)

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit

CVE-2024-5274CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML

CVE-2024-4947CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)

CVE-2024-4671CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox