CVE-2019-17566
12.11.2020, 18:15
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Vendor | Product | Version |
---|---|---|
apache | batik | 𝑥 < 1.13 |
oracle | api_gateway | 11.1.2.4.0 |
oracle | business_intelligence | 5.5.0.0.0 |
oracle | business_intelligence | 5.9.0.0.0 |
oracle | business_intelligence | 12.2.1.3.0 |
oracle | business_intelligence | 12.2.1.4.0 |
oracle | communications_application_session_controller | 3.9m0p2:m0p2 |
oracle | communications_metasolv_solution | 6.3.0 ≤ 𝑥 ≤ 6.3.1 |
oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
oracle | enterprise_repository | 11.1.1.7.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.6 ≤ 𝑥 ≤ 8.1.0 |
oracle | fusion_middleware_mapviewer | 12.2.1.4.0 |
oracle | hospitality_opera_5 | 5.5 |
oracle | hospitality_opera_5 | 5.6 |
oracle | hyperion_financial_reporting | 11.1.2.4 |
oracle | hyperion_financial_reporting | 11.2.5.0 |
oracle | instantis_enterprisetrack | 17.1 ≤ 𝑥 ≤ 17.3 |
oracle | jd_edwards_enterpriseone_tools | 𝑥 < 9.2.4.0 |
oracle | jd_edwards_enterpriseone_tools | 9.2.4.2 |
oracle | retail_integration_bus | 15.0.3 |
oracle | retail_order_broker | 15.0 |
oracle | retail_order_broker | 16.0 |
oracle | retail_order_management_system_cloud_service | 19.5 |
oracle | retail_point-of-service | 14.1 |
oracle | retail_returns_management | 14.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
batik |
|
References