7.5

CVE-2019-17566

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Batik Version < 1.13
Oracle ≫ Api Gateway Version 11.1.2.4.0
Oracle ≫ Business Intelligence Version 5.5.0.0.0 SwEdition enterprise
Oracle ≫ Business Intelligence Version 5.9.0.0.0 SwEdition enterprise
Oracle ≫ Business Intelligence Version 12.2.1.3.0 SwEdition enterprise
Oracle ≫ Business Intelligence Version 12.2.1.4.0 SwEdition enterprise
Oracle ≫ Communications Metasolv Solution Version >= 6.3.0 <= 6.3.1
Oracle ≫ Enterprise Repository Version 11.1.1.7.0
Oracle ≫ Fusion Middleware Mapviewer Version 12.2.1.4.0
Oracle ≫ Hospitality Opera 5 Version 5.5
Oracle ≫ Hospitality Opera 5 Version 5.6
Oracle ≫ Hyperion Financial Reporting Version 11.1.2.4
Oracle ≫ Hyperion Financial Reporting Version 11.2.5.0
Oracle ≫ Instantis Enterprisetrack Version >= 17.1 <= 17.3
Oracle ≫ Jd Edwards Enterpriseone Tools Version < 9.2.4.0
Oracle ≫ Retail Integration Bus Version 15.0.3
Oracle ≫ Retail Order Broker Version 15.0
Oracle ≫ Retail Order Broker Version 16.0
Oracle ≫ Retail Point-of-service Version 14.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.87% 0.954
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

https://www.oracle.com/security-alerts/cpujan2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Patch
Third Party Advisory
https://xmlgraphics.apache.org/security.html
Vendor Advisory
https://security.gentoo.org/glsa/202401-11
https://lists.apache.org/thread.html/rab94fe68b180d2e2fba97abf6fe1ec83cff826be25f86cd90f047171%40%3Ccommits.myfaces.apache.org%3E
https://lists.apache.org/thread.html/rcab14a9ec91aa4c151e0729966282920423eff50a22759fd21db6509%40%3Ccommits.myfaces.apache.org%3E