Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2018-8013

In Apache Batik 1.x before 1.10, when deserializing subclass of AbstractDocument, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
Software From Fixed in
apache / batik 1.0 1.10
debian / debian_linux 8.0 8.0.x
debian / debian_linux 7.0 7.0.x
debian / debian_linux 9.0 9.0.x
canonical / ubuntu_linux 14.04 14.04.x
oracle / jd_edwards_enterpriseone_tools 9.2 9.2.x
oracle / fusion_middleware_mapviewer 12.2.1.2 12.2.1.2.x
oracle / enterprise_repository 12.1.3.0.0 12.1.3.0.0.x
oracle / business_intelligence 11.1.1.9.0 11.1.1.9.0.x
oracle / enterprise_repository 11.1.1.7.0 11.1.1.7.0.x
oracle / business_intelligence 11.1.1.7.0 11.1.1.7.0.x
oracle / retail_back_office 13.4 13.4.x
oracle / retail_back_office 14.1 14.1.x
oracle / retail_back_office 13.3 13.3.x
oracle / business_intelligence 12.2.1.3.0 12.2.1.3.0.x
oracle / communications_diameter_signaling_router - 8.3
oracle / retail_order_broker 5.1 5.1.x
oracle / retail_order_broker 5.2 5.2.x
oracle / retail_order_broker 15.0 15.0.x
oracle / retail_order_broker 16.0 16.0.x
oracle / insurance_calculation_engine 10.2.1 10.2.1.x
oracle / insurance_calculation_engine 10.1.1 10.1.1.x
oracle / retail_returns_management 14.1 14.1.x
oracle / retail_central_office 14.1 14.1.x
oracle / communications_webrtc_session_controller - 7.2
oracle / retail_point-of-service 14.1 14.1.x
oracle / retail_point-of-service 14.0 14.0.x
oracle / retail_point-of-service 13.4 13.4.x
oracle / fusion_middleware_mapviewer 12.2.1.3 12.2.1.3.x
oracle / financial_services_analytical_applications_infrastructure 7.3.3.0.0 7.3.3.0.2.x
oracle / data_integrator 12.2.1.3.0 12.2.1.3.0.x
oracle / business_intelligence 12.2.1.4.0 12.2.1.4.0.x
oracle / instantis_enterprisetrack 17.1 17.1.x
oracle / instantis_enterprisetrack 17.2 17.2.x
oracle / instantis_enterprisetrack 17.3 17.3.x
oracle / retail_integration_bus 17.0 17.0.x
oracle / insurance_policy_administration_j2ee 10.0 10.0.x
oracle / insurance_policy_administration_j2ee 10.2 10.2.x
oracle / retail_back_office 14 14.x
oracle / communications_metasolv_solution 6.3.0 6.3.0.x
oracle / financial_services_analytical_applications_infrastructure 8.0.0.0.0 8.0.7.1.0.x
org.apache.xmlgraphics / batik 1.0 1.10