GHSA-c9jj-3wvg-q65h · Severity: critical · Ecosystem: maven — Vulnerability that affects org.apache.pdfbox:pdfbox
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Conclusion & alert: CVE-2019-0228 is rated High Risk (71.9/100): CVSS Critical severity, with high exploitation likelihood (EPSS 13.03%, 94th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-18 | 13.21% | 13.03% | -0.18% |
| 2 | 2026-01-31 | 13.42% | 13.21% | -0.22% |
| 3 | 2025-11-21 | — | 13.42% | — |
Full EPSS history (22 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-c9jj-3wvg-q65h · Severity: critical · Ecosystem: maven — Vulnerability that affects org.apache.pdfbox:pdfbox
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2019-0228 unimportant priority: Debian including 2 source packages (libpdfbox-java, libpdfbox2-java), 10 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 10. | https://security-tracker.debian.org/tracker/CVE-2019-0228 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2019-0228 |
ubuntu
|
medium | CVE-2019-0228 medium priority: Ubuntu including 2 source packages (libpdfbox-java, libpdfbox2-java), 10 status rows across 5 suites (bionic, cosmic, trusty, upstream, xenial): not-affected 7, DNE 3. | https://ubuntu.com/security/CVE-2019-0228 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | pdfbox | 2.0.14 | cpe:2.3:a:apache:pdfbox:2.0.14:*:*:*:*:*:*:* |
| apache | james | 3.3.0 | cpe:2.3:a:apache:james:3.3.0:*:*:*:*:*:*:* |
| apache | james | 3.4.0 | cpe:2.3:a:apache:james:3.4.0:*:*:*:*:*:*:* |
| fedoraproject | fedora | 29 | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* |
| fedoraproject | fedora | 30 | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
| oracle | banking_corporate_lending_process_management | 14.2 | cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.2:*:*:*:*:*:*:* |
| oracle | banking_corporate_lending_process_management | 14.3 | cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3:*:*:*:*:*:*:* |
| oracle | banking_corporate_lending_process_management | 14.5 | cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5:*:*:*:*:*:*:* |
| oracle | banking_credit_facilities_process_management | 14.2 | cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.2:*:*:*:*:*:*:* |
| oracle | banking_credit_facilities_process_management | 14.3 | cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.3:*:*:*:*:*:*:* |
| oracle | banking_credit_facilities_process_management | 14.5 | cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5:*:*:*:*:*:*:* |
| oracle | banking_supply_chain_finance | 14.2 | cpe:2.3:a:oracle:banking_supply_chain_finance:14.2:*:*:*:*:*:*:* |
| oracle | banking_supply_chain_finance | 14.3 | cpe:2.3:a:oracle:banking_supply_chain_finance:14.3:*:*:*:*:*:*:* |
| oracle | banking_supply_chain_finance | 14.5 | cpe:2.3:a:oracle:banking_supply_chain_finance:14.5:*:*:*:*:*:*:* |
| oracle | banking_trade_finance_process_management | 14.2 | cpe:2.3:a:oracle:banking_trade_finance_process_management:14.2:*:*:*:*:*:*:* |
| oracle | banking_trade_finance_process_management | 14.3 | cpe:2.3:a:oracle:banking_trade_finance_process_management:14.3:*:*:*:*:*:*:* |
| oracle | banking_trade_finance_process_management | 14.5 | cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5:*:*:*:*:*:*:* |
| oracle | banking_virtual_account_management | 14.2 | cpe:2.3:a:oracle:banking_virtual_account_management:14.2:*:*:*:*:*:*:* |
| oracle | banking_virtual_account_management | 14.3.0 | cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:*:*:*:*:*:*:* |
| oracle | banking_virtual_account_management | 14.5 | cpe:2.3:a:oracle:banking_virtual_account_management:14.5:*:*:*:*:*:*:* |
| oracle | communications_messaging_server | 8.1 | cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:* |
| oracle | communications_session_report_manager | >= 8.0.0.0, <= 8.2.4.0 | cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:* |
| oracle | hyperion_financial_reporting | 11.1.2.4 | cpe:2.3:a:oracle:hyperion_financial_reporting:11.1.2.4:*:*:*:*:*:*:* |
| oracle | hyperion_financial_reporting | 11.2.6.0 | cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.6.0:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.58 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.59 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 16.0.6 | cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 17.0 | cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 18.0.3 | cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:* |
| oracle | webcenter_sites | 12.2.1.3.0 | cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | webcenter_sites | 12.2.1.4.0 | cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | communications_messaging_server | 8.1 | cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:* |