CVE-2019-12154

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
11/06/2019
Last modified:
13/06/2019

Description

XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of service conditions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:realobjects:pdfreactor:*:*:*:*:*:*:*:* 10.1.10722 (excluding)