CVE-2019-17566
high · 7.5Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
7.5
CVSS
10.9%
EPSS (exploit prob.)
96th
EPSS percentile
2020-11-12
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses
CWE-918
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | batik | < 1.13 |
| oracle | api_gateway | 11.1.2.4.0 |
| oracle | business_intelligence | 5.5.0.0.0 |
| oracle | business_intelligence | 5.9.0.0.0 |
| oracle | business_intelligence | 12.2.1.3.0 |
| oracle | business_intelligence | 12.2.1.4.0 |
| oracle | communications_application_session_controller | 3.9m0p2 |
| oracle | communications_metasolv_solution | >= 6.3.0, <= 6.3.1 |
| oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
| oracle | enterprise_repository | 11.1.1.7.0 |
| oracle | financial_services_analytical_applications_infrastructure | >= 8.0.6, <= 8.1.0 |
| oracle | fusion_middleware_mapviewer | 12.2.1.4.0 |
| oracle | hospitality_opera_5 | 5.5 |
| oracle | hospitality_opera_5 | 5.6 |
| oracle | hyperion_financial_reporting | 11.1.2.4 |
| oracle | hyperion_financial_reporting | 11.2.5.0 |
| oracle | instantis_enterprisetrack | >= 17.1, <= 17.3 |
| oracle | jd_edwards_enterpriseone_tools | < 9.2.4.0 |
| oracle | jd_edwards_enterpriseone_tools | 9.2.4.2 |
| oracle | retail_integration_bus | 15.0.3 |
| oracle | retail_order_broker | 15.0 |
| oracle | retail_order_broker | 16.0 |
| oracle | retail_order_management_system_cloud_service | 19.5 |
| oracle | retail_point-of-service | 14.1 |
| oracle | retail_returns_management | 14.1 |
Check a specific version with /api/v1/cve/match.
References
- https://lists.apache.org/thread.html/rab94fe68b180d2e2fba97abf6fe1ec83cff826be25f86cd90f047171%40%3Ccommits.myfaces.apache.org%3E
- https://lists.apache.org/thread.html/rcab14a9ec91aa4c151e0729966282920423eff50a22759fd21db6509%40%3Ccommits.myfaces.apache.org%3E
- https://security.gentoo.org/glsa/202401-11
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://xmlgraphics.apache.org/security.html
- https://lists.apache.org/thread.html/rab94fe68b180d2e2fba97abf6fe1ec83cff826be25f86cd90f047171%40%3Ccommits.myfaces.apache.org%3E
- https://lists.apache.org/thread.html/rcab14a9ec91aa4c151e0729966282920423eff50a22759fd21db6509%40%3Ccommits.myfaces.apache.org%3E
- https://security.gentoo.org/glsa/202401-11
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://xmlgraphics.apache.org/security.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-17566