CVE-2018-8013
published 2018-05-24CVE-2018-8013: In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then…
PriorityP357critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
19.52%
97.1th percentile
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | batik | >= 0 < 1.10-1 | 1.10-1 |
| apache | batik | >= 0 < 1.10-1 | 1.10-1 |
| apache | batik | >= 0 < 1.10-1 | 1.10-1 |
| apache | batik | >= 0 < 1.10-1 | 1.10-1 |
| apache | batik | >= 1.0 < 1.10 | 1.10 |
| apache_software_foundation | apache_batik | — | — |
| canonical | ubuntu_linux | — | — |
| debian | batik | < batik 1.10-1 (bookworm) | batik 1.10-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | communications_diameter_signaling_router | < 8.3 | 8.3 |
| oracle | communications_metasolv_solution | — | — |
| oracle | communications_webrtc_session_controller | < 7.2 | 7.2 |
| oracle | data_integrator | — | — |
| oracle | enterprise_repository | — | — |
| oracle | enterprise_repository | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 7.3.3.0.0 – 7.3.3.0.2 | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.0.0.0 – 8.0.7.1.0 | — |
| oracle | fusion_middleware_mapviewer | — | — |
| oracle | fusion_middleware_mapviewer | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_oracle7.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Supply Chain Risk Matrix: Middle Tier (Apache Batik) — CVE-2018-8013
vendor_oracle·2020-07-15·CVSS 7.3
CVE-2018-8013 [CRITICAL] Oracle Oracle Supply Chain Risk Matrix: Middle Tier (Apache Batik) — CVE-2018-8013
Oracle Oracle Supply Chain Risk Matrix: Middle Tier (Apache Batik) vulnerability
CVE: CVE-2018-8013
CVSS: 7.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Ubuntu
Batik vulnerability
vendor_ubuntu·2018-05-29
CVE-2018-8013 Batik vulnerability
Title: Batik vulnerability
Summary: Batik could be made to expose sensitive information if it received
a specially crafted XML.
It was discovered that Batik incorrectly handled certain XML.
An attacker could possibly use this to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
batik: information disclosure when deserializing
vendor_redhat·2018-05-23·CVSS 9.8
CVE-2018-8013 [CRITICAL] CWE-502 batik: information disclosure when deserializing
batik: information disclosure when deserializing
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
Package: batik (Red Hat Enterprise Linux 6) - Will not fix
Package: batik (Red Hat Enterprise Linux 7) - Will not fix
Package: batik (Red Hat Enterprise Linux 8) - Not affected
Package: switchyard (Red Hat JBoss Fuse 6) - Will not fix
Package: rh-java-common-batik (Red Hat Software Collections) - Will not fix
Debian
CVE-2018-8013: batik - In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocumen...
vendor_debian·2018·CVSS 9.8
CVE-2018-8013 [CRITICAL] CVE-2018-8013: batik - In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocumen...
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
Scope: local
bookworm: resolved (fixed in 1.10-1)
bullseye: resolved (fixed in 1.10-1)
forky: resolved (fixed in 1.10-1)
sid: resolved (fixed in 1.10-1)
trixie: resolved (fixed in 1.10-1)
GHSA
Deserialization of Untrusted Data in Apache Batik
ghsa·2022-05-13
CVE-2018-8013 [CRITICAL] CWE-502 Deserialization of Untrusted Data in Apache Batik
Deserialization of Untrusted Data in Apache Batik
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
OSV
Deserialization of Untrusted Data in Apache Batik
osv·2022-05-13
CVE-2018-8013 [CRITICAL] Deserialization of Untrusted Data in Apache Batik
Deserialization of Untrusted Data in Apache Batik
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
OSV
CVE-2018-8013: In Apache Batik 1
osv·2018-05-24·CVSS 9.8
CVE-2018-8013 [CRITICAL] CVE-2018-8013: In Apache Batik 1
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-8013 batik: information disclosure when deserializing
bugzilla·2018-05-23·CVSS 9.8
CVE-2018-8013 [CRITICAL] CVE-2018-8013 batik: information disclosure when deserializing
CVE-2018-8013 batik: information disclosure when deserializing
A flaw was found in Apache Batik versions 1.0 through 1.9.1. An information disclosure when deserializing a subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class.
References:
https://xmlgraphics.apache.org/security.html
http://seclists.org/oss-sec/2018/q2/135
Discussion:
Created batik tracking bugs for this issue:
Affects: fedora-all [bug 1581726]
---
External References:
https://xmlgraphics.apache.org/security.html
http://seclists.org/oss-sec/2018/q2/135
Bugzilla
CVE-2018-8013 batik: information disclosure when deserializing [fedora-all]
bugzilla·2018-05-23·CVSS 9.8
CVE-2018-8013 [CRITICAL] CVE-2018-8013 batik: information disclosure when deserializing [fedora-all]
CVE-2018-8013 batik: information disclosure when deserializing [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/104252http://www.securitytracker.com/id/1040995https://lists.apache.org/thread.html/r9e90b4d1cf6ea87a79bb506541140dfbf4801f4463a7cee08126ee44%40%3Ccommits.xmlgraphics.apache.org%3Ehttps://lists.apache.org/thread.html/rc0a31867796043fbe59113fb654fe8b13309fe04f8935acb8d0fab19%40%3Ccommits.xmlgraphics.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/05/msg00016.htmlhttps://mail-archives.apache.org/mod_mbox/xmlgraphics-batik-dev/201805.mbox/%3c000701d3f28f%24d01860a0%24704921e0%24%40gmail.com%3ehttps://security.gentoo.org/glsa/202401-11https://usn.ubuntu.com/3661-1/https://www.debian.org/security/2018/dsa-4215https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://xmlgraphics.apache.org/security.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/104252http://www.securitytracker.com/id/1040995https://lists.apache.org/thread.html/r9e90b4d1cf6ea87a79bb506541140dfbf4801f4463a7cee08126ee44%40%3Ccommits.xmlgraphics.apache.org%3Ehttps://lists.apache.org/thread.html/rc0a31867796043fbe59113fb654fe8b13309fe04f8935acb8d0fab19%40%3Ccommits.xmlgraphics.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/05/msg00016.htmlhttps://mail-archives.apache.org/mod_mbox/xmlgraphics-batik-dev/201805.mbox/%3c000701d3f28f%24d01860a0%24704921e0%24%40gmail.com%3ehttps://security.gentoo.org/glsa/202401-11https://usn.ubuntu.com/3661-1/https://www.debian.org/security/2018/dsa-4215https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://xmlgraphics.apache.org/security.html
2018-05-24
Published