ZeroHour

CVE-2020-11987

CVSS 3.1
8.2 high
EPSS
13%p96
Published
()
Modified
Description

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Vendors
apachefedoraprojectoracledebian
Products
batik, fedora, agile engineering data management, banking apis, banking digital experience, communications application session controller, communications metasolv solution, communications offline mediation controller, enterprise repository, flexcube universal banking, fusion middleware mapviewer, instantis enterprisetrack
Weakness
CWE-20, CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.