Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| apache | batik | 1.13 | - |
| fedoraproject | fedora | - | - |
| fedoraproject | fedora | - |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
37
Affected Products
25
References
apache / batik
| - |
| oracle | agile_engineering_data_management | - | - |
| oracle | banking_apis | - | - |
| oracle | banking_apis | - | - |
| oracle | banking_apis | - | - |
| oracle | banking_apis | - | - |
| oracle | banking_apis | - | - |
| oracle | banking_digital_experience | - | - |
| oracle | banking_digital_experience | - | - |
| oracle | banking_digital_experience | - | - |
| oracle | banking_digital_experience | - | - |
| oracle | banking_digital_experience | - | - |
| oracle | communications_application_session_controller | - | - |
| oracle | communications_metasolv_solution | - | - |
| oracle | communications_metasolv_solution | - | - |
| oracle | communications_offline_mediation_controller | - | - |
| oracle | enterprise_repository | - | - |
| oracle | flexcube_universal_banking | 14.1.0 - 14.4.0 | - |
| oracle | fusion_middleware_mapviewer | - | - |
| oracle | instantis_enterprisetrack | - | - |
| oracle | instantis_enterprisetrack | - | - |
| oracle | instantis_enterprisetrack | - | - |
| oracle | insurance_policy_administration | 11.0 - 11.3.1 | - |
| oracle | product_lifecycle_analytics | - | - |
| oracle | retail_back_office | - | - |
| oracle | retail_central_office | - | - |
| oracle | retail_order_broker | - | - |
| oracle | retail_order_broker | - | - |
| oracle | retail_order_management_system_cloud_service | - | - |
| oracle | retail_point-of-service | - | - |
| oracle | retail_returns_management | - | - |
| oracle | weblogic_server | - | - |
| oracle | weblogic_server | - | - |
| oracle | weblogic_server | - | - |
| debian | debian_linux | - | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability
Impact