{"id":"CVE-2020-11987","title":"Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel","summary":"Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying serve…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-20","CWE-918"],"vendor":"apache","product":"batik","affected":["batik <= 1.13","fedora = 33","fedora = 34","agile_engineering_data_management = 6.2.1.0","banking_apis = 18.3","banking_apis = 19.1","banking_apis = 19.2","banking_apis = 20.1","banking_apis = 21.1","banking_digital_experience = 18.3","banking_digital_experience = 19.1","banking_digital_experience = 19.2","banking_digital_experience = 20.1","banking_digital_experience = 21.1","communications_application_session_controller = 3.9m0p3","communications_metasolv_solution = 6.3.0","communications_metasolv_solution = 6.3.1","communications_offline_mediation_controller = 12.0.0.3.0","enterprise_repository = 11.1.1.7.0","flexcube_universal_banking >= 14.1.0, <= 14.4.0","fusion_middleware_mapviewer = 12.2.1.4.0","instantis_enterprisetrack = 17.1","instantis_enterprisetrack = 17.2","instantis_enterprisetrack = 17.3","insurance_policy_administration >= 11.0, <= 11.3.1","product_lifecycle_analytics = 3.6.1","retail_back_office = 14.1","retail_central_office = 14.1","retail_order_broker = 15.0","retail_order_broker = 16.0","retail_order_management_system_cloud_service = 19.5","retail_point-of-service = 14.1","retail_returns_management = 14.1","weblogic_server = 12.2.1.3.0","weblogic_server = 12.2.1.4.0","weblogic_server = 14.1.1.0.0","debian_linux = 10.0"],"published":"2021-02-24","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:55.817","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-11987","references":[{"url":"https://lists.apache.org/thread.html/r2877ae10e8be56a3c52d03e373512ddd32f16b863f24c2e22f5a5ba2%40%3Cdev.poi.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r588d05a0790b40a0eb81088252e1e8c1efb99706631421f17038eb05%40%3Cdev.poi.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00021.html","label":"security@apache.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEDID4DAVPECE6O4QQCSIS75BLLBUUAM/","label":"security@apache.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7EAYO5XIHD6OIEA3HPK64UDDBSLNAC5/","label":"security@apache.org"},{"url":"https://security.gentoo.org/glsa/202401-11","label":"security@apache.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"security@apache.org"},{"url":"https://xmlgraphics.apache.org/security.html","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r2877ae10e8be56a3c52d03e373512ddd32f16b863f24c2e22f5a5ba2%40%3Cdev.poi.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r588d05a0790b40a0eb81088252e1e8c1efb99706631421f17038eb05%40%3Cdev.poi.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00006.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEDID4DAVPECE6O4QQCSIS75BLLBUUAM/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7EAYO5XIHD6OIEA3HPK64UDDBSLNAC5/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202401-11","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://xmlgraphics.apache.org/security.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.1328,"epssPercentile":0.963,"ingestedAt":"2026-10-08T23:16:47.315Z","slug":"CVE-2020-11987","body":"## Overview\n\nApache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.\n\n## Affected\n\n- `batik <= 1.13`\n- `fedora = 33`\n- `fedora = 34`\n- `agile_engineering_data_management = 6.2.1.0`\n- `banking_apis = 18.3`\n- `banking_apis = 19.1`\n- `banking_apis = 19.2`\n- `banking_apis = 20.1`\n- `banking_apis = 21.1`\n- `banking_digital_experience = 18.3`\n- `banking_digital_experience = 19.1`\n- `banking_digital_experience = 19.2`\n- `banking_digital_experience = 20.1`\n- `banking_digital_experience = 21.1`\n- `communications_application_session_controller = 3.9m0p3`\n- `communications_metasolv_solution = 6.3.0`\n- `communications_metasolv_solution = 6.3.1`\n- `communications_offline_mediation_controller = 12.0.0.3.0`\n- `enterprise_repository = 11.1.1.7.0`\n- `flexcube_universal_banking >= 14.1.0, <= 14.4.0`\n- `fusion_middleware_mapviewer = 12.2.1.4.0`\n- `instantis_enterprisetrack = 17.1`\n- `instantis_enterprisetrack = 17.2`\n- `instantis_enterprisetrack = 17.3`\n- `insurance_policy_administration >= 11.0, <= 11.3.1`\n- `product_lifecycle_analytics = 3.6.1`\n- `retail_back_office = 14.1`\n- `retail_central_office = 14.1`\n- `retail_order_broker = 15.0`\n- `retail_order_broker = 16.0`\n- `retail_order_management_system_cloud_service = 19.5`\n- `retail_point-of-service = 14.1`\n- `retail_returns_management = 14.1`\n- `weblogic_server = 12.2.1.3.0`\n- `weblogic_server = 12.2.1.4.0`\n- `weblogic_server = 14.1.1.0.0`\n- `debian_linux = 10.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":45.1,"likelihood":2.7,"exploitation":0,"ransomware":0},"changes":[]}