Latest apache batik Vulnerabilities

Apache Batik prior to 1.16 allows RCE when loading untrusted SVG input
ubuntu/batik<1.10-2~18.04.1
ubuntu/batik<1.12-1ubuntu0.1
ubuntu/batik<1.14-1ubuntu0.2
ubuntu/batik<1.14-2ubuntu0.1
ubuntu/batik<1.7.ubuntu-8ubuntu2.14.04.3+
ubuntu/batik<1.8-3ubuntu1+
and 9 more
Apache Batik prior to 1.16 allows RCE via scripting
ubuntu/batik<1.10-2~18.04.1
ubuntu/batik<1.12-1ubuntu0.1
ubuntu/batik<1.7.ubuntu-8ubuntu2.14.04.3+
ubuntu/batik<1.14-1ubuntu0.2
ubuntu/batik<1.14-2ubuntu0.1
ubuntu/batik<1.8-3ubuntu1+
and 9 more
PDFTranscoder does not block external resources
maven/org.apache.xmlgraphics:batik>=1.0<1.15
Apache Batik=1.14
Debian Debian Linux=10.0
=1.14
=10.0
redhat/Batik<1.15
and 7 more
Jar url should be blocked by DefaultScriptSecurity
maven/org.apache.xmlgraphics:batik>=1.0<1.15
Apache Batik=1.14
Debian Debian Linux=10.0
=1.14
=10.0
redhat/Batik<1.15
and 7 more
Server-Side Request Forgery Information Disclosure Vulnerability
maven/org.apache.xmlgraphics:batik>=1.0<1.15
Apache Batik=1.14
Debian Debian Linux=10.0
=1.14
=10.0
redhat/Batik<1.15
and 7 more
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulner...
Apache Batik<=1.13
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Oracle Banking Apis=18.3
Oracle Banking Apis=19.1
Oracle Banking Apis=19.2
and 38 more
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vul...
maven/org.apache.xmlgraphics:batik<1.13
Apache Batik<1.13
Oracle API Gateway=11.1.2.4.0
Oracle Business Intelligence=5.5.0.0.0
Oracle Business Intelligence=5.9.0.0.0
Oracle Business Intelligence=12.2.1.3.0
and 26 more
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of ...
ubuntu/batik<1.10-1
ubuntu/batik<1.7.ubuntu-8ubuntu2.14.04.3
>=1.0<1.10
=7.0
=8.0
=9.0
and 80 more

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203