CVE-2015-0250
published 2015-03-24CVE-2015-0250: XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read…
PriorityP341medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
16.56%
96.7th percentile
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | batik | <= 1.7 | — |
| apache | batik | >= 0 < 1.7+dfsg-5 | 1.7+dfsg-5 |
| apache | batik | >= 0 < 1.7+dfsg-5 | 1.7+dfsg-5 |
| apache | batik | >= 0 < 1.7+dfsg-5 | 1.7+dfsg-5 |
| apache | batik | >= 0 < 1.7+dfsg-5 | 1.7+dfsg-5 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | batik | < batik 1.7+dfsg-5 (bookworm) | batik 1.7+dfsg-5 (bookworm) |
| redhat | jboss_enterprise_brms_platform | <= 6.1.2 | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Input Validation in Apache Batik
osv·2022-05-17
CVE-2015-0250 [MEDIUM] Improper Input Validation in Apache Batik
Improper Input Validation in Apache Batik
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
GHSA
Improper Input Validation in Apache Batik
ghsa·2022-05-17
CVE-2015-0250 [MEDIUM] CWE-20 Improper Input Validation in Apache Batik
Improper Input Validation in Apache Batik
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
OSV
CVE-2015-0250: XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1
osv·2015-03-24·CVSS 6.4
CVE-2015-0250 [MEDIUM] CVE-2015-0250: XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
Ubuntu
Batik vulnerability
vendor_ubuntu·2015-03-25
CVE-2015-0250 Batik vulnerability
Title: Batik vulnerability
Summary: Batik could be made to consume resources or expose sensitive information.
Nicolas Gregoire and Kevin Schaller discovered that Batik would load XML
external entities by default. If a user or automated system were tricked
into opening a specially crafted SVG file, an attacker could possibly
obtain access to arbitrary files or cause resource consumption.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2015-0250: batik - XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conver...
vendor_debian·2015·CVSS 6.4
CVE-2015-0250 [MEDIUM] CVE-2015-0250: batik - XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conver...
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
Scope: local
bookworm: resolved (fixed in 1.7+dfsg-5)
bullseye: resolved (fixed in 1.7+dfsg-5)
forky: resolved (fixed in 1.7+dfsg-5)
sid: resolved (fixed in 1.7+dfsg-5)
trixie: resolved (fixed in 1.7+dfsg-5)
Red Hat
batik: XML External Entity (XXE) injection in SVG parsing
vendor_redhat·2012-07-25·CVSS 6.4
CVE-2015-0250 [MEDIUM] CWE-611 batik: XML External Entity (XXE) injection in SVG parsing
batik: XML External Entity (XXE) injection in SVG parsing
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
It was found that batik was vulnerable to XML External Entity attacks when parsing SVG files. A remote attacker able to send malicious SVG content to the affected server could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Package: batik (Red Hat Enterprise Linux 6) - Will not fix
Package: batik (Red Hat Enterprise Linux 7) - Will not fix
Package: jasperreports-server-pro (Red Hat Enterprise Virtualization 3) - Will
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0138.htmlhttp://packetstormsecurity.com/files/130964/Apache-Batik-XXE-Injection.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0041.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0042.htmlhttp://seclists.org/fulldisclosure/2015/Mar/142http://www-01.ibm.com/support/docview.wss?uid=swg21963275http://www.debian.org/security/2015/dsa-3205http://www.mandriva.com/security/advisories?name=MDVSA-2015:203http://www.securitytracker.com/id/1032781http://www.ubuntu.com/usn/USN-2548-1http://xmlgraphics.apache.org/security.htmlhttp://advisories.mageia.org/MGASA-2015-0138.htmlhttp://packetstormsecurity.com/files/130964/Apache-Batik-XXE-Injection.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0041.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0042.htmlhttp://seclists.org/fulldisclosure/2015/Mar/142http://www-01.ibm.com/support/docview.wss?uid=swg21963275http://www.debian.org/security/2015/dsa-3205http://www.mandriva.com/security/advisories?name=MDVSA-2015:203http://www.securitytracker.com/id/1032781http://www.ubuntu.com/usn/USN-2548-1http://xmlgraphics.apache.org/security.html
2015-03-24
Published