CVE-2017-5662
published 2017-04-18CVE-2017-5662: In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG…
PriorityP343high7.3CVSS 3.0
AVNACLPRLUIRSUCHINAH
EPSS
4.12%
89.7th percentile
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | batik | <= 1.8 | — |
| apache | batik | >= 0 < 1.9-1 | 1.9-1 |
| apache | batik | >= 0 < 1.9-1 | 1.9-1 |
| apache | batik | >= 0 < 1.9-1 | 1.9-1 |
| apache | batik | >= 0 < 1.9-1 | 1.9-1 |
| apache_software_foundation | apache_batik | — | — |
| debian | batik | < batik 1.9-1 (bookworm) | batik 1.9-1 (bookworm) |
CVSS provenance
nvdv3.07.3HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
nvdv2.07.9HIGHAV:N/AC:M/Au:S/C:C/I:N/A:C
osv7.3HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Batik vulnerability
vendor_ubuntu·2017-05-09
CVE-2017-5662 Apache Batik vulnerability
Title: Apache Batik vulnerability
Summary: Apache Batik would allow unintended access to files over the network or
could be made to crash.
Lars Krapf and Pierre Ernst discovered that Apache Batik incorrectly
handled XML external entities. A remote attacker could possibly use this
issue to obtain sensitive files from the filesystem, or cause a denial of
service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
batik: XML external entity processing vulnerability
vendor_redhat·2017-04-10·CVSS 7.3
CVE-2017-5662 [HIGH] CWE-611 batik: XML external entity processing vulnerability
batik: XML external entity processing vulnerability
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
An XXE vulnerability was found in Apache Batik which could allow a remote attacker to retrieve the files on the vulnerable server's filesystem by uploading specially crafted SVG images.
Debian
CVE-2017-5662: batik - In Apache Batik before 1.9, files lying on the filesystem of the server which us...
vendor_debian·2017·CVSS 7.3
CVE-2017-5662 [HIGH] CVE-2017-5662: batik - In Apache Batik before 1.9, files lying on the filesystem of the server which us...
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
Scope: local
bookworm: resolved (fixed in 1.9-1)
bullseye: resolved (fixed in 1.9-1)
forky: resolved (fixed in 1.9-1)
sid: resolved (fixed in 1.9-1)
trixie: resolved (fixed in 1.9-1)
GHSA
Improper Restriction of XML External Entity Reference in Apache Batik
ghsa·2022-05-13
CVE-2017-5662 [HIGH] CWE-611 Improper Restriction of XML External Entity Reference in Apache Batik
Improper Restriction of XML External Entity Reference in Apache Batik
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
OSV
Improper Restriction of XML External Entity Reference in Apache Batik
osv·2022-05-13
CVE-2017-5662 [HIGH] Improper Restriction of XML External Entity Reference in Apache Batik
Improper Restriction of XML External Entity Reference in Apache Batik
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
OSV
CVE-2017-5662: In Apache Batik before 1
osv·2017-04-18·CVSS 7.3
CVE-2017-5662 [HIGH] CVE-2017-5662: In Apache Batik before 1
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5662 batik: XML external entity processing vulnerability [fedora-all]
bugzilla·2017-04-19·CVSS 7.3
CVE-2017-5662 [HIGH] CVE-2017-5662 batik: XML external entity processing vulnerability [fedora-all]
CVE-2017-5662 batik: XML external entity processing vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2017-5662 batik: XML external entity processing vulnerability
bugzilla·2017-04-19·CVSS 7.3
CVE-2017-5662 [HIGH] CVE-2017-5662 batik: XML external entity processing vulnerability
CVE-2017-5662 batik: XML external entity processing vulnerability
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
References:
https://xmlgraphics.apache.org/security.html
http://seclists.org/oss-sec/2017/q2/85
Discussion:
Created batik tracking bugs for this issue:
Affects: fedora-
arXiv
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
arxiv_fulltext·2025-11-28
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
Aayush Garg
[email protected]
0000-0002-2507-8846
Luxembourg Institute of Science and Technology
Luxembourg
Zanis Ali Khan
[email protected]
0000-0002-3935-2148
Luxembourg Institute of Science and Technology
Luxembourg
Renzo Degiovanni
[email protected]
0000-0003-1611-3969
Luxembourg Institute of Science and Technology
Luxembourg
Qiang Tang
[email protected]
0000-0002-6153-4255
Luxembourg Institute of Science and Technology
Luxembourg
## Abstract
Automated vulnerability patching is crucial for software security, and recent advancements in Large Language Models (LLMs) present promising capabilities for automating this task. However, existing research has primarily assessed LLMs using public
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/97948http://www.securitytracker.com/id/1038334https://access.redhat.com/errata/RHSA-2017:2546https://access.redhat.com/errata/RHSA-2017:2547https://access.redhat.com/errata/RHSA-2018:0319https://www.debian.org/security/2018/dsa-4215https://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://xmlgraphics.apache.org/security.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/97948http://www.securitytracker.com/id/1038334https://access.redhat.com/errata/RHSA-2017:2546https://access.redhat.com/errata/RHSA-2017:2547https://access.redhat.com/errata/RHSA-2018:0319https://www.debian.org/security/2018/dsa-4215https://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://xmlgraphics.apache.org/security.html
2017-04-18
Published