CVE-2018-8013
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
Affected (41)
Show all products
Apache: Batik · Debian: Debian Linux · Canonical: Ubuntu Linux · Oracle: Business Intelligence, Communications Diameter Signaling Router, Communications Metasolv Solution, Communications Webrtc Session Controller, Data Integrator, Enterprise Repository, Financial Services Analytical Applications Infrastructure, Fusion Middleware Mapviewer, Instantis Enterprisetrack, Insurance Calculation Engine, Insurance Policy Administration J2ee, Jd Edwards Enterpriseone Tools, Retail Back Office, Retail Central Office, Retail Integration Bus, Retail Order Broker, Retail Point Of Service, Retail Returns Management
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.1.1.7.0 | |
| Before 8.3 | |
| Version 6.3.0 | |
| Before 7.2 | |
| Version 12.2.1.3.0 | |
| Version 11.1.1.7.0 | |
| From 7.3.3.0.0 to 7.3.3.0.2 | |
| Version 12.2.1.2 | |
| Version 17.1 | |
| Version 10.1.1 | |
| Version 10.0 | |
| Version 9.2 | |
| Version 13.3 | |
| Version 14.1 | |
| Version 17.0 | |
| Version 15.0 | |
| Version 13.4 | |
| Version 14.1 |
References (34)
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.