← Back

CVE-2020-11987

nvd nist
Published: Feb 24, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability: 3.9 / Impact: 4.2
Source: NVD

Description

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Affected (37)

Show all products
1 product
Batik
1 product
Fedora
19 products
Agile Engineering Data Management
Banking Apis
Banking Digital Experience
Communications Metasolv Solution
Enterprise Repository
Flexcube Universal Banking
Fusion Middleware Mapviewer
Instantis Enterprisetrack
Insurance Policy Administration
Product Lifecycle Analytics
Retail Back Office
Retail Central Office
Retail Order Broker
Retail Point Of Service
Retail Returns Management
Weblogic Server
1 product
Debian Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.13
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Configuration C
33 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.2.1.0
Oracle
Version 18.3
Version 19.1
Version 19.2
Version 20.1
Version 21.1
Oracle
Version 18.3
Version 19.1
Version 19.2
Version 20.1
Version 21.1
Version 3.9m0p3
Oracle
Version 6.3.0
Version 6.3.1
Version 12.0.0.3.0
Version 11.1.1.7.0
From 14.1.0 to 14.4.0
Version 12.2.1.4.0
Oracle
Version 17.1
Version 17.2
Version 17.3
From 11.0 to 11.3.1
Version 3.6.1
Version 14.1
Version 14.1
Oracle
Version 15.0
Version 16.0
Version 19.5
Version 14.1
Version 14.1
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 14.1.1.0.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0

References (25)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.