ZeroHour

CVE-2018-8013

CVSS 3.0
9.8 critical
EPSS
19%p97
Published
()
Modified
Description

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

Vendors
apachedebiancanonicaloracle
Products
batik, debian linux, ubuntu linux, business intelligence, communications diameter signaling router, communications metasolv solution, communications webrtc session controller, data integrator, enterprise repository, financial services analytical applications infrastructure, fusion middleware mapviewer, instantis enterprisetrack
Weakness
CWE-502
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.