CVE-2020-11987
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability: 3.9 / Impact: 4.2
Source: NVD
Description
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Affected (37)
Products: Apache: Batik · Fedoraproject: Fedora · Oracle: Agile Engineering Data Management, Banking Apis, Banking Digital Experience, Communications Application Session Controller, Communications Metasolv Solution, Communications Offline Mediation Controller, Enterprise Repository, Flexcube Universal Banking, Fusion Middleware Mapviewer, Instantis Enterprisetrack, Insurance Policy Administration, Product Lifecycle Analytics, Retail Back Office, Retail Central Office, Retail Order Broker, Retail Order Management System Cloud Service, Retail Point Of Service, Retail Returns Management, Weblogic Server · +1 more
Show all products
Apache: Batik · Fedoraproject: Fedora · Oracle: Agile Engineering Data Management, Banking Apis, Banking Digital Experience, Communications Application Session Controller, Communications Metasolv Solution, Communications Offline Mediation Controller, Enterprise Repository, Flexcube Universal Banking, Fusion Middleware Mapviewer, Instantis Enterprisetrack, Insurance Policy Administration, Product Lifecycle Analytics, Retail Back Office, Retail Central Office, Retail Order Broker, Retail Order Management System Cloud Service, Retail Point Of Service, Retail Returns Management, Weblogic Server · Debian: Debian Linux
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 33 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2.1.0 | |
| Version 18.3 | |
| Version 18.3 | |
| Version 3.9m0p3 | |
| Version 6.3.0 | |
| Version 12.0.0.3.0 | |
| Version 11.1.1.7.0 | |
| From 14.1.0 to 14.4.0 | |
| Version 12.2.1.4.0 | |
| Version 17.1 | |
| From 11.0 to 11.3.1 | |
| Version 3.6.1 | |
| Version 14.1 | |
| Version 14.1 | |
| Version 15.0 | |
| Version 19.5 | |
| Version 14.1 | |
| Version 14.1 | |
| Version 12.2.1.3.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
References (25)
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Timeline
No history available yet.