Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13637
HistoryApr 15, 2019 - 1:56 a.m.

XML External Entity (XXE)

2019-04-1501:56:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.006 Low

EPSS

Percentile

79.3%

Apache PDFBox is vulnerable to XML external entity (XXE) attacks. The XML parser does not disable external DTDs, which would allow an attacker to perform XXE attacks using a malicious XFDF file.

CPENameOperatorVersion
apache pdfboxeq2.0.14
apache pdfboxeq2.0.14

References