9.8
CVE-2019-0228
- EPSS 9.45%
- Veröffentlicht 17.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:32
- Erkennungen
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Oracle ≫ Banking Corporate Lending Process Management Version 14.2
Oracle ≫ Banking Corporate Lending Process Management Version 14.3
Oracle ≫ Banking Corporate Lending Process Management Version 14.5
Oracle ≫ Banking Credit Facilities Process Management Version 14.2
Oracle ≫ Banking Credit Facilities Process Management Version 14.3
Oracle ≫ Banking Credit Facilities Process Management Version 14.5
Oracle ≫ Banking Supply Chain Finance Version 14.2
Oracle ≫ Banking Supply Chain Finance Version 14.3
Oracle ≫ Banking Supply Chain Finance Version 14.5
Oracle ≫ Banking Trade Finance Process Management Version 14.2
Oracle ≫ Banking Trade Finance Process Management Version 14.3
Oracle ≫ Banking Trade Finance Process Management Version 14.5
Oracle ≫ Banking Virtual Account Management Version 14.2
Oracle ≫ Banking Virtual Account Management Version 14.3.0
Oracle ≫ Banking Virtual Account Management Version 14.5
Oracle ≫ Communications Messaging Server Version 8.1
Oracle ≫ Communications Session Report Manager Version >= 8.0.0.0 <= 8.2.4.0
Oracle ≫ Hyperion Financial Reporting Version 11.1.2.4
Oracle ≫ Hyperion Financial Reporting Version 11.2.6.0
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.58
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.59
Oracle ≫ Retail Xstore Point Of Service Version 16.0.6
Oracle ≫ Retail Xstore Point Of Service Version 17.0
Oracle ≫ Retail Xstore Point Of Service Version 18.0.3
Oracle ≫ Webcenter Sites Version 12.2.1.3.0
Oracle ≫ Webcenter Sites Version 12.2.1.4.0
Oracle ≫ Communications Messaging Server Version 8.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.45% | 0.948 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6HKVPTJWZGUB4MH4AAOWMRJHRDBYFHGJ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/
https://lists.apache.org/thread.html/1a3756557f8cb02790b7183ccf7665ae23f608a421c4f723113bca79%40%3Cusers.pdfbox.apache.org%3E
https://lists.apache.org/thread.html/8a19bd6d43e359913341043c2a114f91f9e4ae170059539ad1f5673c%40%3Ccommits.tika.apache.org%3E
https://lists.apache.org/thread.html/bc8db1bf459f1ad909da47350ed554ee745abe9f25f2b50cad4e06dd%40%3Cserver-dev.james.apache.org%3E
https://lists.apache.org/thread.html/be86fcd7cd423a3fe6b73a3cb9d7cac0b619d0deb99e6b5d172c98f4%40%3Ccommits.tika.apache.org%3E
https://lists.apache.org/thread.html/r0a2141abeddae66dd57025f1681c8425834062b7c0c7e0b1d830a95d%40%3Cusers.pdfbox.apache.org%3E
https://lists.apache.org/thread.html/r32b8102392a174b17fd19509a9e76047f74852b77b7bf46af95e45a2%40%3Cserver-dev.james.apache.org%3E