CVE-2019-0228: Apache James
Critical severity, CVSS 9.8. EPSS: 9.5% chance of exploitation in the next 30 days.
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Affected products
- Apache James: version 3.3.0 only; version 3.4.0 only
- Apache Pdfbox: version 2.0.14 only
- Fedoraproject Fedora: version 29 only; version 30 only
- Oracle Banking Corporate Lending Process Management: version 14.2 only; version 14.3 only; version 14.5 only
- Oracle Banking Credit Facilities Process Management: version 14.2 only; version 14.3 only; version 14.5 only
- Oracle Banking Supply Chain Finance: version 14.2 only; version 14.3 only; version 14.5 only
- Oracle Banking Trade Finance Process Management: version 14.2 only; version 14.3 only; version 14.5 only
- Oracle Banking Virtual Account Management: version 14.2 only; version 14.3.0 only; version 14.5 only
- Oracle Communications Messaging Server: version 8.1 only
- Oracle Communications Session Report Manager: from 8.0.0.0, up to and including 8.2.4.0
- Oracle Hyperion Financial Reporting: version 11.1.2.4 only; version 11.2.6.0 only
- Oracle PeopleSoft Enterprise PeopleTools: version 8.58 only; version 8.59 only
- Oracle Retail Xstore Point Of Service: version 16.0.6 only; version 17.0 only; version 18.0.3 only
- Oracle Webcenter Sites: version 12.2.1.3.0 only; version 12.2.1.4.0 only
Published 2019-04-17. Last modified 2026-06-17.