CVE-2019-0228: Apache James

Critical severity, CVSS 9.8. EPSS: 9.5% chance of exploitation in the next 30 days.

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

Affected products

  • Apache James: version 3.3.0 only; version 3.4.0 only
  • Apache Pdfbox: version 2.0.14 only
  • Fedoraproject Fedora: version 29 only; version 30 only
  • Oracle Banking Corporate Lending Process Management: version 14.2 only; version 14.3 only; version 14.5 only
  • Oracle Banking Credit Facilities Process Management: version 14.2 only; version 14.3 only; version 14.5 only
  • Oracle Banking Supply Chain Finance: version 14.2 only; version 14.3 only; version 14.5 only
  • Oracle Banking Trade Finance Process Management: version 14.2 only; version 14.3 only; version 14.5 only
  • Oracle Banking Virtual Account Management: version 14.2 only; version 14.3.0 only; version 14.5 only
  • Oracle Communications Messaging Server: version 8.1 only
  • Oracle Communications Session Report Manager: from 8.0.0.0, up to and including 8.2.4.0
  • Oracle Hyperion Financial Reporting: version 11.1.2.4 only; version 11.2.6.0 only
  • Oracle PeopleSoft Enterprise PeopleTools: version 8.58 only; version 8.59 only
  • Oracle Retail Xstore Point Of Service: version 16.0.6 only; version 17.0 only; version 18.0.3 only
  • Oracle Webcenter Sites: version 12.2.1.3.0 only; version 12.2.1.4.0 only

Published 2019-04-17. Last modified 2026-06-17.