HIGH · 7.5

CVE-2019-17566

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vul...

Vulnerability Description

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
ApacheBatik< 1.13
OracleApi Gateway11.1.2.4.0
OracleBusiness Intelligence5.5.0.0.0
OracleCommunications Application Session Controller3.9m0p2
OracleCommunications Metasolv Solution>= 6.3.0, <= 6.3.1
OracleCommunications Offline Mediation Controller12.0.0.3.0
OracleEnterprise Repository11.1.1.7.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6, <= 8.1.0
OracleFusion Middleware Mapviewer12.2.1.4.0
OracleHospitality Opera 55.5
OracleHyperion Financial Reporting11.1.2.4
OracleInstantis Enterprisetrack>= 17.1, <= 17.3
OracleJd Edwards Enterpriseone Tools< 9.2.4.0
OracleRetail Integration Bus15.0.3
OracleRetail Order Broker15.0
OracleRetail Order Management System Cloud Service19.5
OracleRetail Point-Of-Service14.1
OracleRetail Returns Management14.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-17566?

CVE-2019-17566 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vul...

How severe is CVE-2019-17566?

CVE-2019-17566 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-17566?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Batik, Oracle Api Gateway, Oracle Business Intelligence, Oracle Communications Application Session Controller, Oracle Communications Metasolv Solution.