HIGH · 8.2

CVE-2020-11987

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulner...

Vulnerability Description

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVSS Score

8.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
ApacheBatik<= 1.13
FedoraprojectFedora33
OracleAgile Engineering Data Management6.2.1.0
OracleBanking Apis18.3
OracleBanking Digital Experience18.3
OracleCommunications Application Session Controller3.9m0p3
OracleCommunications Metasolv Solution6.3.0
OracleCommunications Offline Mediation Controller12.0.0.3.0
OracleEnterprise Repository11.1.1.7.0
OracleFlexcube Universal Banking>= 14.1.0, <= 14.4.0
OracleFusion Middleware Mapviewer12.2.1.4.0
OracleInstantis Enterprisetrack17.1
OracleInsurance Policy Administration>= 11.0, <= 11.3.1
OracleProduct Lifecycle Analytics3.6.1
OracleRetail Back Office14.1
OracleRetail Central Office14.1
OracleRetail Order Broker15.0
OracleRetail Order Management System Cloud Service19.5
OracleRetail Point-Of-Service14.1
OracleRetail Returns Management14.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11987?

CVE-2020-11987 is a vulnerability with a CVSS score of 8.2 (HIGH). Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulner...

How severe is CVE-2020-11987?

CVE-2020-11987 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11987?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Batik, Fedoraproject Fedora, Oracle Agile Engineering Data Management, Oracle Banking Apis, Oracle Banking Digital Experience.