CVE-2020-11987
—CVSS 3.1
8.2 high
EPSS
13%p96
Published
()
Modified
Description
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
- Vendors
- apachefedoraprojectoracledebian
- Products
- batik, fedora, agile engineering data management, banking apis, banking digital experience, communications application session controller, communications metasolv solution, communications offline mediation controller, enterprise repository, flexcube universal banking, fusion middleware mapviewer, instantis enterprisetrack
- Weakness
- CWE-20, CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.