CVE-2018-8013
—CVSS 3.0
9.8 critical
EPSS
19%p97
Published
()
Modified
Description
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
- Vendors
- apachedebiancanonicaloracle
- Products
- batik, debian linux, ubuntu linux, business intelligence, communications diameter signaling router, communications metasolv solution, communications webrtc session controller, data integrator, enterprise repository, financial services analytical applications infrastructure, fusion middleware mapviewer, instantis enterprisetrack
- Weakness
- CWE-502
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.