Rewterz

Rewterz Threat Alert – Muddy Water Resurfaces with Fresher Indicators of Compromise

April 15, 2019
Rewterz

Rewterz Threat Advisory – VMware ESXi Multiple Vulnerabilities

April 15, 2019

Rewterz Threat Advisory – CVE-2019-0228 – Apache PDFBox XML External Entity Vulnerability

Severity

Medium

Analysis Summary


An error within the XML parser when parsing XML entities can be exploited to disclose certain data or cause a DoS condition via a specially crafted XML document including external entity references.

Impact

  • Denial of Service
  • Exposure of sensitive information

Affected Vendors

Apache Foundation

Affected Products

Apache PDFBox 2.x

Remediation

Update to version 2.0.15.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.