CVE-2020-11987
24.02.2021, 18:15
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.Enginsight
Vendor | Product | Version |
---|---|---|
apache | batik | 𝑥 ≤ 1.13 |
oracle | agile_engineering_data_management | 6.2.1.0 |
oracle | banking_apis | 18.3 |
oracle | banking_apis | 19.1 |
oracle | banking_apis | 19.2 |
oracle | banking_apis | 20.1 |
oracle | banking_apis | 21.1 |
oracle | banking_digital_experience | 18.3 |
oracle | banking_digital_experience | 19.1 |
oracle | banking_digital_experience | 19.2 |
oracle | banking_digital_experience | 20.1 |
oracle | banking_digital_experience | 21.1 |
oracle | communications_application_session_controller | 3.9m0p3:m0p3 |
oracle | communications_metasolv_solution | 6.3.0 |
oracle | communications_metasolv_solution | 6.3.1 |
oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
oracle | enterprise_repository | 11.1.1.7.0 |
oracle | flexcube_universal_banking | 14.1.0 ≤ 𝑥 ≤ 14.4.0 |
oracle | fusion_middleware_mapviewer | 12.2.1.4.0 |
oracle | instantis_enterprisetrack | 17.1 |
oracle | instantis_enterprisetrack | 17.2 |
oracle | instantis_enterprisetrack | 17.3 |
oracle | insurance_policy_administration | 11.0 ≤ 𝑥 ≤ 11.3.1 |
oracle | product_lifecycle_analytics | 3.6.1 |
oracle | retail_back_office | 14.1 |
oracle | retail_central_office | 14.1 |
oracle | retail_order_broker | 15.0 |
oracle | retail_order_broker | 16.0 |
oracle | retail_order_management_system_cloud_service | 19.5 |
oracle | retail_point-of-service | 14.1 |
oracle | retail_returns_management | 14.1 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
oracle | weblogic_server | 14.1.1.0.0 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
batik |
|
Common Weakness Enumeration
References