---
id: CVE-2020-11987
title: >-
  Apache Batik 1.13 is vulnerable to server-side request forgery, caused by
  improper input validation by the NodePickerPanel
summary: >-
  Apache Batik 1.13 is vulnerable to server-side request forgery, caused by
  improper input validation by the NodePickerPanel. By using a specially-crafted
  argument, an attacker could exploit this vulnerability to cause the underlying
  serve…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-20
  - CWE-918
vendor: apache
product: batik
affected:
  - batik <= 1.13
  - fedora = 33
  - fedora = 34
  - agile_engineering_data_management = 6.2.1.0
  - banking_apis = 18.3
  - banking_apis = 19.1
  - banking_apis = 19.2
  - banking_apis = 20.1
  - banking_apis = 21.1
  - banking_digital_experience = 18.3
  - banking_digital_experience = 19.1
  - banking_digital_experience = 19.2
  - banking_digital_experience = 20.1
  - banking_digital_experience = 21.1
  - communications_application_session_controller = 3.9m0p3
  - communications_metasolv_solution = 6.3.0
  - communications_metasolv_solution = 6.3.1
  - communications_offline_mediation_controller = 12.0.0.3.0
  - enterprise_repository = 11.1.1.7.0
  - 'flexcube_universal_banking >= 14.1.0, <= 14.4.0'
  - fusion_middleware_mapviewer = 12.2.1.4.0
  - instantis_enterprisetrack = 17.1
  - instantis_enterprisetrack = 17.2
  - instantis_enterprisetrack = 17.3
  - 'insurance_policy_administration >= 11.0, <= 11.3.1'
  - product_lifecycle_analytics = 3.6.1
  - retail_back_office = 14.1
  - retail_central_office = 14.1
  - retail_order_broker = 15.0
  - retail_order_broker = 16.0
  - retail_order_management_system_cloud_service = 19.5
  - retail_point-of-service = 14.1
  - retail_returns_management = 14.1
  - weblogic_server = 12.2.1.3.0
  - weblogic_server = 12.2.1.4.0
  - weblogic_server = 14.1.1.0.0
  - debian_linux = 10.0
published: '2021-02-24'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:55.817'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-11987'
references:
  - url: >-
      https://lists.apache.org/thread.html/r2877ae10e8be56a3c52d03e373512ddd32f16b863f24c2e22f5a5ba2%40%3Cdev.poi.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r588d05a0790b40a0eb81088252e1e8c1efb99706631421f17038eb05%40%3Cdev.poi.apache.org%3E
    label: security@apache.org
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00021.html'
    label: security@apache.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEDID4DAVPECE6O4QQCSIS75BLLBUUAM/
    label: security@apache.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7EAYO5XIHD6OIEA3HPK64UDDBSLNAC5/
    label: security@apache.org
  - url: 'https://security.gentoo.org/glsa/202401-11'
    label: security@apache.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: security@apache.org
  - url: 'https://xmlgraphics.apache.org/security.html'
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r2877ae10e8be56a3c52d03e373512ddd32f16b863f24c2e22f5a5ba2%40%3Cdev.poi.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r588d05a0790b40a0eb81088252e1e8c1efb99706631421f17038eb05%40%3Cdev.poi.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2025/07/msg00006.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEDID4DAVPECE6O4QQCSIS75BLLBUUAM/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7EAYO5XIHD6OIEA3HPK64UDDBSLNAC5/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202401-11'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://xmlgraphics.apache.org/security.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.1328
epssPercentile: 0.963
ingestedAt: '2026-10-08T23:16:47.315Z'
---

## Overview

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

## Affected

- `batik <= 1.13`
- `fedora = 33`
- `fedora = 34`
- `agile_engineering_data_management = 6.2.1.0`
- `banking_apis = 18.3`
- `banking_apis = 19.1`
- `banking_apis = 19.2`
- `banking_apis = 20.1`
- `banking_apis = 21.1`
- `banking_digital_experience = 18.3`
- `banking_digital_experience = 19.1`
- `banking_digital_experience = 19.2`
- `banking_digital_experience = 20.1`
- `banking_digital_experience = 21.1`
- `communications_application_session_controller = 3.9m0p3`
- `communications_metasolv_solution = 6.3.0`
- `communications_metasolv_solution = 6.3.1`
- `communications_offline_mediation_controller = 12.0.0.3.0`
- `enterprise_repository = 11.1.1.7.0`
- `flexcube_universal_banking >= 14.1.0, <= 14.4.0`
- `fusion_middleware_mapviewer = 12.2.1.4.0`
- `instantis_enterprisetrack = 17.1`
- `instantis_enterprisetrack = 17.2`
- `instantis_enterprisetrack = 17.3`
- `insurance_policy_administration >= 11.0, <= 11.3.1`
- `product_lifecycle_analytics = 3.6.1`
- `retail_back_office = 14.1`
- `retail_central_office = 14.1`
- `retail_order_broker = 15.0`
- `retail_order_broker = 16.0`
- `retail_order_management_system_cloud_service = 19.5`
- `retail_point-of-service = 14.1`
- `retail_returns_management = 14.1`
- `weblogic_server = 12.2.1.3.0`
- `weblogic_server = 12.2.1.4.0`
- `weblogic_server = 14.1.1.0.0`
- `debian_linux = 10.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
