CVE-2019-17566
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Affected (25)
Products: Apache: Batik · Oracle: Api Gateway, Business Intelligence, Communications Application Session Controller, Communications Metasolv Solution, Communications Offline Mediation Controller, Enterprise Repository, Financial Services Analytical Applications Infrastructure, Fusion Middleware Mapviewer, Hospitality Opera 5, Hyperion Financial Reporting, Instantis Enterprisetrack, Jd Edwards Enterpriseone Tools, Retail Integration Bus, Retail Order Broker, Retail Order Management System Cloud Service, Retail Point Of Service, Retail Returns Management
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.1.2.4.0 | |
| Version 12.2.1.3.0 | |
| Version 3.9m0p2 | |
| From 6.3.0 to 6.3.1 | |
| Version 12.0.0.3.0 | |
| Version 11.1.1.7.0 | |
| From 8.0.6 to 8.1.0 | |
| Version 12.2.1.4.0 | |
| Version 5.5 | |
| Version 11.1.2.4 | |
| From 17.1 to 17.3 | |
| Before 9.2.4.0 | |
| Version 15.0.3 | |
| Version 15.0 | |
| Version 19.5 | |
| Version 14.1 | |
| Version 14.1 |
References (20)
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.