CVE-2018-8013
24.05.2018, 16:29
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.Enginsight
Vendor | Product | Version |
---|---|---|
apache | batik | 1.0 ≤ 𝑥 < 1.10 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
canonical | ubuntu_linux | 14.04 |
oracle | business_intelligence | 11.1.1.7.0 |
oracle | business_intelligence | 11.1.1.9.0 |
oracle | business_intelligence | 12.2.1.3.0 |
oracle | business_intelligence | 12.2.1.4.0 |
oracle | communications_diameter_signaling_router | 𝑥 < 8.3 |
oracle | communications_metasolv_solution | 6.3.0 |
oracle | communications_webrtc_session_controller | 𝑥 < 7.2 |
oracle | data_integrator | 12.2.1.3.0 |
oracle | enterprise_repository | 11.1.1.7.0 |
oracle | enterprise_repository | 12.1.3.0.0 |
oracle | financial_services_analytical_applications_infrastructure | 7.3.3.0.0 ≤ 𝑥 ≤ 7.3.3.0.2 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.0.0.0 ≤ 𝑥 ≤ 8.0.7.1.0 |
oracle | fusion_middleware_mapviewer | 12.2.1.2 |
oracle | fusion_middleware_mapviewer | 12.2.1.3 |
oracle | instantis_enterprisetrack | 17.1 |
oracle | instantis_enterprisetrack | 17.2 |
oracle | instantis_enterprisetrack | 17.3 |
oracle | insurance_calculation_engine | 10.1.1 |
oracle | insurance_calculation_engine | 10.2.1 |
oracle | insurance_policy_administration_j2ee | 10.0 |
oracle | insurance_policy_administration_j2ee | 10.2 |
oracle | jd_edwards_enterpriseone_tools | 9.2 |
oracle | retail_back_office | 13.3 |
oracle | retail_back_office | 13.4 |
oracle | retail_back_office | 14.1 |
oracle | retail_central_office | 14.1 |
oracle | retail_integration_bus | 17.0 |
oracle | retail_order_broker | 5.1 |
oracle | retail_order_broker | 5.2 |
oracle | retail_order_broker | 15.0 |
oracle | retail_order_broker | 16.0 |
oracle | retail_point-of-service | 13.4 |
oracle | retail_point-of-service | 14.0 |
oracle | retail_point-of-service | 14.1 |
oracle | retail_returns_management | 14.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
batik |
|
Common Weakness Enumeration
References