5
CVSSv2

CVE-2019-17566

Published: 12/11/2020 Updated: 07/01/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache batik

oracle api gateway 11.1.2.4.0

oracle hyperion financial reporting 11.1.2.4

oracle enterprise repository 11.1.1.7.0

oracle business intelligence 12.2.1.3.0

oracle retail order broker 15.0

oracle retail order broker 16.0

oracle retail returns management 14.1

oracle retail point-of-service 14.1

oracle business intelligence 12.2.1.4.0

oracle business intelligence 5.5.0.0.0

oracle financial services analytical applications infrastructure

oracle fusion middleware mapviewer 12.2.1.4.0

oracle instantis enterprisetrack

oracle communications offline mediation controller 12.0.0.3.0

oracle retail integration bus 15.0.3

oracle communications application session controller 3.9m0p2

oracle hospitality opera 5 5.5

oracle hospitality opera 5 5.6

oracle business intelligence 5.9.0.0.0

oracle retail order management system cloud service 19.5

oracle jd edwards enterpriseone tools

oracle communications metasolv solution

oracle jd edwards enterpriseone tools 9.2.4.2

oracle hyperion financial reporting 11.2.5.0

Vendor Advisories

Debian Bug report logs - #964510 batik: CVE-2019-17566 Package: batik; Maintainer for batik is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Emilio Pozuelo Monfort <pochu@debianorg> Date: Wed, 8 Jul 2020 08:15:01 UTC Severity: important Tags: security Found in version 18-4 ...
Synopsis Moderate: Red Hat Process Automation Manager 790 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring ...
Synopsis Important: Red Hat Fuse 780 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 77 to 78) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Produc ...
Synopsis Moderate: Red Hat Decision Manager 790 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Decision ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [CVE-2019-17566] Apache XML Graphics Batik SSRF vulnerability <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: "Si ...

Github Repositories

A cheatsheet for exploiting server-side SVG rasterization.

SVG rasterization cheatsheet SVG rasterization cheatsheet XLink:Href references Documents Images Fonts ICC profiles Stylesheets XML stylesheet CSS @import CSS infinite loading via @import rule Infinite loading using /dev/random Tags styles using fill attribute Scripting Embedded scripts Script tag Events External scripts Code execution XML External Entities Li