CVE-2020-11987

Description

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Software From Fixed in
debian / debian_linux 10.0 10.0.x
fedoraproject / fedora 33 33.x
fedoraproject / fedora 34 34.x
oracle / weblogic_server 12.2.1.3.0 12.2.1.3.0.x
oracle / weblogic_server 12.2.1.4.0 12.2.1.4.0.x
oracle / weblogic_server 14.1.1.0.0 14.1.1.0.0.x
oracle / communications_application_session_controller 3.9m0p3 3.9m0p3.x
apache / batik - 1.13.x
oracle / fusion_middleware_mapviewer 12.2.1.4.0 12.2.1.4.0.x
oracle / agile_engineering_data_management 6.2.1.0 6.2.1.0.x
oracle / retail_order_management_system_cloud_service 19.5 19.5.x
oracle / retail_order_broker 15.0 15.0.x
oracle / retail_order_broker 16.0 16.0.x
oracle / flexcube_universal_banking 14.1.0 14.4.0.x
oracle / enterprise_repository 11.1.1.7.0 11.1.1.7.0.x
oracle / retail_point-of-service 14.1 14.1.x
oracle / retail_back_office 14.1 14.1.x
oracle / instantis_enterprisetrack 17.1 17.1.x
oracle / instantis_enterprisetrack 17.2 17.2.x
oracle / instantis_enterprisetrack 17.3 17.3.x
oracle / insurance_policy_administration 11.0 11.3.1.x
oracle / retail_central_office 14.1 14.1.x
oracle / retail_returns_management 14.1 14.1.x
oracle / communications_metasolv_solution 6.3.0 6.3.0.x
oracle / communications_metasolv_solution 6.3.1 6.3.1.x
oracle / banking_digital_experience 18.3 18.3.x
oracle / banking_digital_experience 19.1 19.1.x
oracle / banking_digital_experience 19.2 19.2.x
oracle / banking_digital_experience 20.1 20.1.x
oracle / banking_digital_experience 21.1 21.1.x
oracle / banking_apis 18.3 18.3.x
oracle / banking_apis 19.1 19.1.x
oracle / banking_apis 19.2 19.2.x
oracle / banking_apis 20.1 20.1.x
oracle / banking_apis 21.1 21.1.x
oracle / communications_offline_mediation_controller 12.0.0.3.0 12.0.0.3.0.x
oracle / product_lifecycle_analytics 3.6.1 3.6.1.x
org.apache.xmlgraphics / batik-util - 1.14
org.apache.xmlgraphics / batik-xml - 1.14
org.apache.xmlgraphics / batik-ttf2svg - 1.14