CVE-2018-8013

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
apachebatik
1.0 ≤
𝑥
< 1.10
debiandebian_linux
7.0
debiandebian_linux
8.0
debiandebian_linux
9.0
canonicalubuntu_linux
14.04
oraclebusiness_intelligence
11.1.1.7.0
oraclebusiness_intelligence
11.1.1.9.0
oraclebusiness_intelligence
12.2.1.3.0
oraclebusiness_intelligence
12.2.1.4.0
oraclecommunications_diameter_signaling_router
𝑥
< 8.3
oraclecommunications_metasolv_solution
6.3.0
oraclecommunications_webrtc_session_controller
𝑥
< 7.2
oracledata_integrator
12.2.1.3.0
oracleenterprise_repository
11.1.1.7.0
oracleenterprise_repository
12.1.3.0.0
oraclefinancial_services_analytical_applications_infrastructure
7.3.3.0.0 ≤
𝑥
≤ 7.3.3.0.2
oraclefinancial_services_analytical_applications_infrastructure
8.0.0.0.0 ≤
𝑥
≤ 8.0.7.1.0
oraclefusion_middleware_mapviewer
12.2.1.2
oraclefusion_middleware_mapviewer
12.2.1.3
oracleinstantis_enterprisetrack
17.1
oracleinstantis_enterprisetrack
17.2
oracleinstantis_enterprisetrack
17.3
oracleinsurance_calculation_engine
10.1.1
oracleinsurance_calculation_engine
10.2.1
oracleinsurance_policy_administration_j2ee
10.0
oracleinsurance_policy_administration_j2ee
10.2
oraclejd_edwards_enterpriseone_tools
9.2
oracleretail_back_office
13.3
oracleretail_back_office
13.4
oracleretail_back_office
14.1
oracleretail_central_office
14.1
oracleretail_integration_bus
17.0
oracleretail_order_broker
5.1
oracleretail_order_broker
5.2
oracleretail_order_broker
15.0
oracleretail_order_broker
16.0
oracleretail_point-of-service
13.4
oracleretail_point-of-service
14.0
oracleretail_point-of-service
14.1
oracleretail_returns_management
14.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
batik
bullseye
1.12-4+deb11u2
fixed
bullseye (security)
1.12-4+deb11u1
fixed
bookworm
1.16+dfsg-1+deb12u1
fixed
sid
1.18+dfsg-2
fixed
trixie
1.18+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
batik
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
ignored
xenial
needed
trusty
Fixed 1.7.ubuntu-8ubuntu2.14.04.3
released
References