CRITICAL · 9.8

CVE-2018-8013

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of ...

Vulnerability Description

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ApacheBatik>= 1.0, < 1.10
DebianDebian Linux7.0
CanonicalUbuntu Linux14.04
OracleBusiness Intelligence11.1.1.7.0
OracleCommunications Diameter Signaling Router< 8.3
OracleCommunications Metasolv Solution6.3.0
OracleCommunications Webrtc Session Controller< 7.2
OracleData Integrator12.2.1.3.0
OracleEnterprise Repository11.1.1.7.0
OracleFinancial Services Analytical Applications Infrastructure>= 7.3.3.0.0, <= 7.3.3.0.2
OracleFusion Middleware Mapviewer12.2.1.2
OracleInstantis Enterprisetrack17.1
OracleInsurance Calculation Engine10.1.1
OracleInsurance Policy Administration J2Ee10.0
OracleJd Edwards Enterpriseone Tools9.2
OracleRetail Back Office13.3
OracleRetail Central Office14.1
OracleRetail Integration Bus17.0
OracleRetail Order Broker5.1
OracleRetail Point-Of-Service13.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-8013?

CVE-2018-8013 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of ...

How severe is CVE-2018-8013?

CVE-2018-8013 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-8013?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Batik, Debian Debian Linux, Canonical Ubuntu Linux, Oracle Business Intelligence, Oracle Communications Diameter Signaling Router.