Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
01 Feb 2024, 01:24
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.gentoo.org/glsa/202401-11 - Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEDID4DAVPECE6O4QQCSIS75BLLBUUAM/ - Mailing List, Third Party Advisory | |
References | () https://lists.apache.org/thread.html/r588d05a0790b40a0eb81088252e1e8c1efb99706631421f17038eb05%40%3Cdev.poi.apache.org%3E - Mailing List, Vendor Advisory | |
References | (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00021.html - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7EAYO5XIHD6OIEA3HPK64UDDBSLNAC5/ - Mailing List, Third Party Advisory | |
References | () https://lists.apache.org/thread.html/r2877ae10e8be56a3c52d03e373512ddd32f16b863f24c2e22f5a5ba2%40%3Cdev.poi.apache.org%3E - Mailing List, Vendor Advisory | |
References | (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - Patch, Third Party Advisory | |
CPE | cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:* |
|
First Time |
Debian debian Linux
Oracle product Lifecycle Analytics Oracle weblogic Server Debian Oracle agile Engineering Data Management |
07 Jan 2024, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Nov 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
15 Oct 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2021-02-24 18:15
Updated : 2024-02-28 18:08
NVD link : CVE-2020-11987
Mitre link : CVE-2020-11987
CVE.ORG link : CVE-2020-11987
JSON object : View
Products Affected
oracle
- enterprise_repository
- agile_engineering_data_management
- insurance_policy_administration
- retail_order_management_system_cloud_service
- communications_metasolv_solution
- fusion_middleware_mapviewer
- banking_apis
- communications_offline_mediation_controller
- communications_application_session_controller
- retail_order_broker
- retail_point-of-service
- product_lifecycle_analytics
- weblogic_server
- retail_back_office
- instantis_enterprisetrack
- retail_central_office
- banking_digital_experience
- flexcube_universal_banking
- retail_returns_management
fedoraproject
- fedora
debian
- debian_linux
apache
- batik