CVE-2015-0250XML External Entity (XXE) Injection in Apache Batik

Severity
6.4MEDIUMNVD
EPSS
1.5%
top 19.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateMay 17

Description

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

CVSS vector

AV:N/AC:L/C:P/I:N/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

Debianapache/batik< 1.7+dfsg-5+3
NVDapache/batik1.7

Also affects: Ubuntu Linux 12.04, 14.04, 14.10

Patches

🔴Vulnerability Details

4
OSV
Improper Input Validation in Apache Batik2022-05-17
GHSA
Improper Input Validation in Apache Batik2022-05-17
OSV
CVE-2015-0250: XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 12015-03-24
CVEList
CVE-2015-0250: XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 12015-03-24

📋Vendor Advisories

3
Ubuntu
Batik vulnerability2015-03-25
Debian
CVE-2015-0250: batik - XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conver...2015
Red Hat
batik: XML External Entity (XXE) injection in SVG parsing2012-07-25

💬Community

1
Bugzilla
CVE-2015-0250 batik: XML External Entity (XXE) injection in SVG parsing2015-03-19
CVE-2015-0250 — XML External Entity (XXE) Injection | cvebase