An XXE vulnerability was found in Apache Batik which could allow a remote attacker to retrieve the files on the vulnerable server's filesystem by uploading specially crafted SVG images. The vulnerability could also allow a denial of service condition by performing an amplification attack.
Find out more about CVE-2017-5662 from the MITRE CVE dictionary dictionary and NIST NVD.
The batik package is no longer used or required by the Red Hat Virtualization Manager. Red Hat recommends removing it after updating to Red Hat Virtualization 4.1.
CVSS3 Base Score | 7.5 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity Impact | None |
Availability Impact | None |
Platform | Errata | Release Date |
---|---|---|
Red Hat JBoss BRMS 6.4 | RHSA-2017:2547 | 2017-08-29 |
Red Hat JBoss A-MQ 6.3 | RHSA-2018:0319 | 2018-02-14 |
Red Hat JBoss BPMS 6.4 | RHSA-2017:2546 | 2017-08-29 |
Red Hat JBoss Fuse 6.3 | RHSA-2018:0319 | 2018-02-14 |
Platform | Package | State |
---|---|---|
Red Hat Virtualization 4 | batik | Will not fix |
Red Hat Software Collections for Red Hat Enterprise Linux | rh-java-common-batik | Will not fix |
Red Hat JBoss Fuse Service Works 6 | batik | Will not fix |
Red Hat Enterprise Linux 7 | batik | Will not fix |
Red Hat Enterprise Linux 6 | batik | Will not fix |