CVE-2020-11987High· 8.2▾ TwilightApache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying serve…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 2.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
13%
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
batik <= 1.13fedora = 33fedora = 34agile_engineering_data_management = 6.2.1.0banking_apis = 18.3banking_apis = 19.1banking_apis = 19.2banking_apis = 20.1banking_apis = 21.1banking_digital_experience = 18.3banking_digital_experience = 19.1banking_digital_experience = 19.2banking_digital_experience = 20.1banking_digital_experience = 21.1communications_application_session_controller = 3.9m0p3communications_metasolv_solution = 6.3.0communications_metasolv_solution = 6.3.1communications_offline_mediation_controller = 12.0.0.3.0enterprise_repository = 11.1.1.7.0flexcube_universal_banking >= 14.1.0, <= 14.4.0fusion_middleware_mapviewer = 12.2.1.4.0instantis_enterprisetrack = 17.1instantis_enterprisetrack = 17.2instantis_enterprisetrack = 17.3insurance_policy_administration >= 11.0, <= 11.3.1product_lifecycle_analytics = 3.6.1retail_back_office = 14.1retail_central_office = 14.1retail_order_broker = 15.0retail_order_broker = 16.0retail_order_management_system_cloud_service = 19.5retail_point-of-service = 14.1retail_returns_management = 14.1weblogic_server = 12.2.1.3.0weblogic_server = 12.2.1.4.0weblogic_server = 14.1.1.0.0debian_linux = 10.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2020-13956Medium· 5.3Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
CVE-2021-29425Medium· 4.8In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…
CVE-2021-3572Medium· 5.7A flaw was found in python-pip in the way it handled Unicode separators in git references
CVE-2021-21985Critical· 9.8The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server
CVE-2021-41079High· 7.5Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets