ZeroHour

CVE-2019-17566

CVSS 3.1
7.5 high
EPSS
11%p96
Published
()
Modified
Description

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Vendors
apacheoracle
Products
batik, api gateway, business intelligence, communications application session controller, communications metasolv solution, communications offline mediation controller, enterprise repository, financial services analytical applications infrastructure, fusion middleware mapviewer, hospitality opera 5, hyperion financial reporting, instantis enterprisetrack
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.