CVE-2019-17566
—CVSS 3.1
7.5 high
EPSS
11%p96
Published
()
Modified
Description
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
- Vendors
- apacheoracle
- Products
- batik, api gateway, business intelligence, communications application session controller, communications metasolv solution, communications offline mediation controller, enterprise repository, financial services analytical applications infrastructure, fusion middleware mapviewer, hospitality opera 5, hyperion financial reporting, instantis enterprisetrack
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.