Rewterz
Rewterz Threat Alert – Muddy Water Resurfaces with Fresher Indicators of Compromise
April 15, 2019
Rewterz
Rewterz Threat Advisory – VMware ESXi Multiple Vulnerabilities
April 15, 2019

Rewterz Threat Advisory – CVE-2019-0228 – Apache PDFBox XML External Entity Vulnerability

Severity

Medium

Analysis Summary


An error within the XML parser when parsing XML entities can be exploited to disclose certain data or cause a DoS condition via a specially crafted XML document including external entity references.

Impact

  • Denial of Service
  • Exposure of sensitive information

Affected Vendors

Apache Foundation

Affected Products

Apache PDFBox 2.x

Remediation

Update to version 2.0.15.