Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| apache | batik | 1.13 | - |
| oracle | api_gateway | - | - |
| oracle | business_intelligence | - |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
25
Affected Products
20
References
apache / batik
| - |
| oracle | business_intelligence | - | - |
| oracle | business_intelligence | - | - |
| oracle | business_intelligence | - | - |
| oracle | communications_application_session_controller | - | - |
| oracle | communications_metasolv_solution | 6.3.0 - 6.3.1 | - |
| oracle | communications_offline_mediation_controller | - | - |
| oracle | enterprise_repository | - | - |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6 - 8.1.0 | - |
| oracle | fusion_middleware_mapviewer | - | - |
| oracle | hospitality_opera_5 | - | - |
| oracle | hospitality_opera_5 | - | - |
| oracle | hyperion_financial_reporting | - | - |
| oracle | hyperion_financial_reporting | - | - |
| oracle | instantis_enterprisetrack | 17.1 - 17.3 | - |
| oracle | jd_edwards_enterpriseone_tools | 9.2.4.0 | - |
| oracle | jd_edwards_enterpriseone_tools | - | - |
| oracle | retail_integration_bus | - | - |
| oracle | retail_order_broker | - | - |
| oracle | retail_order_broker | - | - |
| oracle | retail_order_management_system_cloud_service | - | - |
| oracle | retail_point-of-service | - | - |
| oracle | retail_returns_management | - | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability
Impact