← All CVEs

CVE-2018-8013

critical · 9.8

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

9.8
CVSS
19.3%
EPSS (exploit prob.)
97th
EPSS percentile
2018-05-24
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
apachebatik>= 1.0, < 1.10
debiandebian_linux7.0
debiandebian_linux8.0
debiandebian_linux9.0
canonicalubuntu_linux14.04
oraclebusiness_intelligence11.1.1.7.0
oraclebusiness_intelligence11.1.1.9.0
oraclebusiness_intelligence12.2.1.3.0
oraclebusiness_intelligence12.2.1.4.0
oraclecommunications_diameter_signaling_router< 8.3
oraclecommunications_metasolv_solution6.3.0
oraclecommunications_webrtc_session_controller< 7.2
oracledata_integrator12.2.1.3.0
oracleenterprise_repository11.1.1.7.0
oracleenterprise_repository12.1.3.0.0
oraclefinancial_services_analytical_applications_infrastructure>= 7.3.3.0.0, <= 7.3.3.0.2
oraclefinancial_services_analytical_applications_infrastructure>= 8.0.0.0.0, <= 8.0.7.1.0
oraclefusion_middleware_mapviewer12.2.1.2
oraclefusion_middleware_mapviewer12.2.1.3
oracleinstantis_enterprisetrack17.1
oracleinstantis_enterprisetrack17.2
oracleinstantis_enterprisetrack17.3
oracleinsurance_calculation_engine10.1.1
oracleinsurance_calculation_engine10.2.1
oracleinsurance_policy_administration_j2ee10.0
oracleinsurance_policy_administration_j2ee10.2
oraclejd_edwards_enterpriseone_tools9.2
oracleretail_back_office13.3
oracleretail_back_office13.4
oracleretail_back_office14
oracleretail_back_office14.1
oracleretail_central_office14.1
oracleretail_integration_bus17.0
oracleretail_order_broker5.1
oracleretail_order_broker5.2
oracleretail_order_broker15.0
oracleretail_order_broker16.0
oracleretail_point-of-service13.4
oracleretail_point-of-service14.0
oracleretail_point-of-service14.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-8013