{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-02T16:46:00.957","vulnerabilities":[{"cve":{"id":"CVE-2019-0228","sourceIdentifier":"security@apache.org","published":"2019-04-17T15:29:00.703","lastModified":"2024-11-21T04:16:32.607","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF."},{"lang":"es","value":"Apache PDFBox versión 2.0.14 no inicializa correctamente el analizador XML, lo que permite a los atacantes dependientes del contexto realizar ataques de Entidades Externas XML (XXE) por medio  de un XFDF creado."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-611"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:pdfbox:2.0.14:*:*:*:*:*:*:*","matchCriteriaId":"F8ECE6C6-5387-4750-9F67-DBBC039269D2"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:james:3.3.0:*:*:*:*:*:*:*","matchCriteriaId":"E8786909-2255-4799-BBCD-8B4618F5CEB8"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:james:3.4.0:*:*:*:*:*:*:*","matchCriteriaId":"7E307B96-C1A9-46DC-83AF-F7DFE074BAD8"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*","matchCriteriaId":"D100F7CE-FC64-4CC6-852A-6136D72DA419"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*","matchCriteriaId":"97A4B8DF-58DA-4AB6-A1F9-331B36409BA3"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.2:*:*:*:*:*:*:*","matchCriteriaId":"55543515-BE87-4D88-8F9B-130FCE792642"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3:*:*:*:*:*:*:*","matchCriteriaId":"0D32FE52-C11F-40F0-943A-4FD1241AA599"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5:*:*:*:*:*:*:*","matchCriteriaId":"6EE231C5-8BF0-48F4-81EF-7186814664CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.2:*:*:*:*:*:*:*","matchCriteriaId":"F9284BB0-343D-46DE-B45D-68081BC20225"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.3:*:*:*:*:*:*:*","matchCriteriaId":"821A1FAA-6475-4892-97A5-10D434BC2C9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5:*:*:*:*:*:*:*","matchCriteriaId":"2AA5FF83-B693-4DAB-B585-0FD641266231"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_supply_chain_finance:14.2:*:*:*:*:*:*:*","matchCriteriaId":"1D99F81D-61BB-4904-BE31-3367D4A98FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_supply_chain_finance:14.3:*:*:*:*:*:*:*","matchCriteriaId":"93866792-1AAE-40AE-84D0-21250A296BE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_supply_chain_finance:14.5:*:*:*:*:*:*:*","matchCriteriaId":"45AB3A29-0994-46F4-8093-B4A9CE0BD95F"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_trade_finance_process_management:14.2:*:*:*:*:*:*:*","matchCriteriaId":"2CA1E217-7551-4718-A813-7F55927C7829"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_trade_finance_process_management:14.3:*:*:*:*:*:*:*","matchCriteriaId":"DE39702F-0176-4C0E-96BA-A344319776B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5:*:*:*:*:*:*:*","matchCriteriaId":"AA4A9041-B9BC-451C-B1BD-4E2FD795BF27"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_virtual_account_management:14.2:*:*:*:*:*:*:*","matchCriteriaId":"D97050DD-2299-4480-A274-914EC6693E40"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:*:*:*:*:*:*:*","matchCriteriaId":"D952E04D-DE2D-4AE0-BFE6-7D9B7E55AC80"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_virtual_account_management:14.5:*:*:*:*:*:*:*","matchCriteriaId":"E2696CD1-9514-405D-A3B3-8308EC1FA571"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*","matchCriteriaId":"E1214FDF-357A-4BB9-BADE-50FB2BD16D10"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0.0","versionEndIncluding":"8.2.4.0","matchCriteriaId":"F80CB000-C477-486C-838C-B2FE82647670"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:hyperion_financial_reporting:11.1.2.4:*:*:*:*:*:*:*","matchCriteriaId":"0A6675A3-684B-4486-A451-C6688F1C821B"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.6.0:*:*:*:*:*:*:*","matchCriteriaId":"ED543A4C-B774-4578-AC5B-752434EAF197"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*","matchCriteriaId":"D9DB4A14-2EF5-4B54-95D2-75E6CF9AA0A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*","matchCriteriaId":"C8AF00C6-B97F-414D-A8DF-057E6BFD8597"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:*","matchCriteriaId":"490B2C44-CECD-4551-B04F-4076D0E053C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0:*:*:*:*:*:*:*","matchCriteriaId":"55AE3629-4A66-49E4-A33D-6D81CC94962F"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:*","matchCriteriaId":"48EFC111-B01B-4C34-87E4-D6B2C40C0122"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:*","matchCriteriaId":"D551CAB1-4312-44AA-BDA8-A030817E153A"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*","matchCriteriaId":"174A6D2E-E42E-4C92-A194-C6A820CD7EF4"},{"vulnerable":true,"criteria":"cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*","matchCriteriaId":"7569C0BD-16C1-441E-BAEB-840C94BE73EF"}]}]}],"references":[{"url":"https://lists.apache.org/thread.html/1a3756557f8cb02790b7183ccf7665ae23f608a421c4f723113bca79%40%3Cusers.pdfbox.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/8a19bd6d43e359913341043c2a114f91f9e4ae170059539ad1f5673c%40%3Ccommits.tika.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/bc8db1bf459f1ad909da47350ed554ee745abe9f25f2b50cad4e06dd%40%3Cserver-dev.james.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/be86fcd7cd423a3fe6b73a3cb9d7cac0b619d0deb99e6b5d172c98f4%40%3Ccommits.tika.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r0a2141abeddae66dd57025f1681c8425834062b7c0c7e0b1d830a95d%40%3Cusers.pdfbox.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r32b8102392a174b17fd19509a9e76047f74852b77b7bf46af95e45a2%40%3Cserver-dev.james.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6HKVPTJWZGUB4MH4AAOWMRJHRDBYFHGJ/","source":"security@apache.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/","source":"security@apache.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://lists.apache.org/thread.html/1a3756557f8cb02790b7183ccf7665ae23f608a421c4f723113bca79%40%3Cusers.pdfbox.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/8a19bd6d43e359913341043c2a114f91f9e4ae170059539ad1f5673c%40%3Ccommits.tika.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/bc8db1bf459f1ad909da47350ed554ee745abe9f25f2b50cad4e06dd%40%3Cserver-dev.james.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/be86fcd7cd423a3fe6b73a3cb9d7cac0b619d0deb99e6b5d172c98f4%40%3Ccommits.tika.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r0a2141abeddae66dd57025f1681c8425834062b7c0c7e0b1d830a95d%40%3Cusers.pdfbox.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r32b8102392a174b17fd19509a9e76047f74852b77b7bf46af95e45a2%40%3Cserver-dev.james.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6HKVPTJWZGUB4MH4AAOWMRJHRDBYFHGJ/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}