CVE-2020-11987
published 2021-02-24CVE-2020-11987: Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted…
PriorityP261high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
13.63%
96.1th percentile
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | batik | <= 1.13 | — |
| apache | batik | >= 0 < 1.12-4+deb11u3 | 1.12-4+deb11u3 |
| apache | batik | >= 0 < 1.14-1 | 1.14-1 |
| apache | batik | >= 0 < 1.14-1 | 1.14-1 |
| apache | batik | >= 0 < 1.14-1 | 1.14-1 |
| apache | batik | >= 0 < 1.10-2~18.04.1 | 1.10-2~18.04.1 |
| apache | batik | >= 0 < 1.12-1ubuntu0.1 | 1.12-1ubuntu0.1 |
| apache | batik | >= 0 < 1.14-1ubuntu0.2 | 1.14-1ubuntu0.2 |
| apache | batik | >= 0 < 1.7.ubuntu-8ubuntu2.14.04.3+esm1 | 1.7.ubuntu-8ubuntu2.14.04.3+esm1 |
| apache | batik | >= 0 < 1.8-3ubuntu1+esm1 | 1.8-3ubuntu1+esm1 |
| debian | batik | < batik 1.14-1 (bookworm) | batik 1.14-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via improper input validation by the NodePickerPanel component in Apache Batik 1.13; monitor for unexpected outbound GET requests originating from the server process handling Batik/SVG rendering. ↗
- ·Vulnerability is confirmed in Apache Batik 1.13; fixed versions are 1.14+ (Debian: fixed in 1.14-1 for bookworm/forky/sid/trixie, and 1.12-4+deb11u3 for bullseye). Upgrade to 1.14 or later to remediate. ↗
- ·Exploitation is remote and occurs over HTTP; the attack vector is network-based with no authentication required (CVSS 8.2 in several Oracle advisories), making internet-exposed Batik instances at highest risk. ↗
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv8.2HIGH
vendor_debian8.2HIGH
vendor_oracle8.2HIGH
vendor_redhat8.2HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Batik vulnerabilities
vendor_ubuntu·2023-05-30·CVSS 7.5
CVE-2022-40146 [HIGH] Apache Batik vulnerabilities
Title: Apache Batik vulnerabilities
Summary: Several security issues were fixed in Apache Batik.
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Logger (Apache Batik) — CVE-2020-11987
vendor_oracle·2023-04-15·CVSS 8.2
CVE-2020-11987 [HIGH] Oracle Oracle Insurance Applications Risk Matrix: Logger (Apache Batik) — CVE-2020-11987
Oracle Oracle Insurance Applications Risk Matrix: Logger (Apache Batik) vulnerability
CVE: CVE-2020-11987
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party Patch (Apache Batik) — CVE-2020-11987
vendor_oracle·2023-01-15·CVSS 8.2
CVE-2020-11987 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Third Party Patch (Apache Batik) — CVE-2020-11987
Oracle Oracle Fusion Middleware Risk Matrix: Third Party Patch (Apache Batik) vulnerability
CVE: CVE-2020-11987
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Data Model Risk Matrix: Utilities (Apache Batik) — CVE-2020-11987
vendor_oracle·2022-10-15·CVSS 4.3
CVE-2020-11987 [HIGH] Oracle Oracle Communications Data Model Risk Matrix: Utilities (Apache Batik) — CVE-2020-11987
Oracle Oracle Communications Data Model Risk Matrix: Utilities (Apache Batik) vulnerability
CVE: CVE-2020-11987
CVSS: 4.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third Party Jars (Apache Batik) — CVE-2020-11987
vendor_oracle·2022-07-15·CVSS 8.2
CVE-2020-11987 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third Party Jars (Apache Batik) — CVE-2020-11987
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third Party Jars (Apache Batik) vulnerability
CVE: CVE-2020-11987
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Framework (Apache Batik) — CVE-2020-11987
vendor_oracle·2022-01-15·CVSS 8.2
CVE-2020-11987 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Framework (Apache Batik) — CVE-2020-11987
Oracle Oracle Financial Services Applications Risk Matrix: Framework (Apache Batik) vulnerability
CVE: CVE-2020-11987
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Architecture (Apache Batik) — CVE-2020-11987
vendor_oracle·2021-10-15·CVSS 8.2
CVE-2020-11987 [HIGH] Oracle Oracle Insurance Applications Risk Matrix: Architecture (Apache Batik) — CVE-2020-11987
Oracle Oracle Insurance Applications Risk Matrix: Architecture (Apache Batik) vulnerability
CVE: CVE-2020-11987
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: UDC CORE (Apache Batik) — CVE-2020-11987
vendor_oracle·2021-07-15·CVSS 5.3
CVE-2020-11987 [HIGH] Oracle Oracle Communications Applications Risk Matrix: UDC CORE (Apache Batik) — CVE-2020-11987
Oracle Oracle Communications Applications Risk Matrix: UDC CORE (Apache Batik) vulnerability
CVE: CVE-2020-11987
CVSS: 5.3
Protocol: TCP/IP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Planning and Modeling (Apache Batik) — CVE-2020-11987
vendor_oracle·2021-04-15·CVSS 5.3
CVE-2020-11987 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Planning and Modeling (Apache Batik) — CVE-2020-11987
Oracle Oracle Communications Applications Risk Matrix: Planning and Modeling (Apache Batik) vulnerability
CVE: CVE-2020-11987
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Red Hat
batik: SSRF due to improper input validation by the NodePickerPanel
vendor_redhat·2021-02-24·CVSS 8.2
CVE-2020-11987 [HIGH] CWE-918 batik: SSRF due to improper input validation by the NodePickerPanel
batik: SSRF due to improper input validation by the NodePickerPanel
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: batik (Red Hat Enterprise Linux 6) - Out of support scope
Package: batik (Red Hat Enterprise Linux 7) - Out of support scope
Package: eclipse:rhel8/batik (Red Hat Enterprise Linux 8) - Not affected
Pa
Debian
CVE-2020-11987: batik - Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improp...
vendor_debian·2020·CVSS 8.2
CVE-2020-11987 [HIGH] CVE-2020-11987: batik - Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improp...
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Scope: local
bookworm: resolved (fixed in 1.14-1)
bullseye: resolved (fixed in 1.12-4+deb11u3)
forky: resolved (fixed in 1.14-1)
sid: resolved (fixed in 1.14-1)
trixie: resolved (fixed in 1.14-1)
OSV
batik vulnerabilities
osv·2023-05-30·CVSS 7.5
CVE-2019-17566 [HIGH] batik vulnerabilities
batik vulnerabilities
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
GHSA
Server-side request forgery (SSRF) in Apache Batik
ghsa·2022-01-06
CVE-2020-11987 [HIGH] CWE-20 Server-side request forgery (SSRF) in Apache Batik
Server-side request forgery (SSRF) in Apache Batik
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
OSV
Server-side request forgery (SSRF) in Apache Batik
osv·2022-01-06
CVE-2020-11987 [HIGH] Server-side request forgery (SSRF) in Apache Batik
Server-side request forgery (SSRF) in Apache Batik
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
OSV
CVE-2020-11987: Apache Batik 1
osv·2021-02-24·CVSS 8.2
CVE-2020-11987 [HIGH] CVE-2020-11987: Apache Batik 1
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread.html/r2877ae10e8be56a3c52d03e373512ddd32f16b863f24c2e22f5a5ba2%40%3Cdev.poi.apache.org%3Ehttps://lists.apache.org/thread.html/r588d05a0790b40a0eb81088252e1e8c1efb99706631421f17038eb05%40%3Cdev.poi.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2023/10/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEDID4DAVPECE6O4QQCSIS75BLLBUUAM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7EAYO5XIHD6OIEA3HPK64UDDBSLNAC5/https://security.gentoo.org/glsa/202401-11https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://xmlgraphics.apache.org/security.htmlhttps://lists.apache.org/thread.html/r2877ae10e8be56a3c52d03e373512ddd32f16b863f24c2e22f5a5ba2%40%3Cdev.poi.apache.org%3Ehttps://lists.apache.org/thread.html/r588d05a0790b40a0eb81088252e1e8c1efb99706631421f17038eb05%40%3Cdev.poi.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2023/10/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2025/07/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEDID4DAVPECE6O4QQCSIS75BLLBUUAM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7EAYO5XIHD6OIEA3HPK64UDDBSLNAC5/https://security.gentoo.org/glsa/202401-11https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://xmlgraphics.apache.org/security.html
2021-02-24
Published