CVE-2019-12154: Realobjects Pdfreactor
Critical severity, CVSS 9.1. EPSS: 2% chance of exploitation in the next 30 days.
XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of service conditions.
Affected products
- Realobjects Pdfreactor: before 10.1.10722 (fixed in 10.1.10722)
Published 2019-06-11. Last modified 2026-06-17.