Apache Software Foundation Apache Batik vulnerabilities
2 known vulnerabilities affecting apache_software_foundation/apache_batik.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2018-8013CRITICALCVSS 9.8v1.0 - 1.9.12018-05-24
CVE-2018-8013 [CRITICAL] CWE-502 CVE-2018-8013: In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
cvelistv5nvd
CVE-2017-5662HIGHCVSS 7.3vbefore 1.92017-04-18
CVE-2017-5662 [HIGH] CWE-611 CVE-2017-5662: In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be reve
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sen
cvelistv5nvd