8.2
CVE-2020-11987
- EPSS 13.64%
- Veröffentlicht 24.02.2021 18:15:11
- Zuletzt bearbeitet 03.11.2025 20:15:42
- Erkennungen
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 33
Fedoraproject ≫ Fedora Version 34
Oracle ≫ Agile Engineering Data Management Version 6.2.1.0
Oracle ≫ Banking Apis Version 18.3
Oracle ≫ Banking Apis Version 19.1
Oracle ≫ Banking Apis Version 19.2
Oracle ≫ Banking Apis Version 20.1
Oracle ≫ Banking Apis Version 21.1
Oracle ≫ Banking Digital Experience Version 18.3
Oracle ≫ Banking Digital Experience Version 19.1
Oracle ≫ Banking Digital Experience Version 19.2
Oracle ≫ Banking Digital Experience Version 20.1
Oracle ≫ Banking Digital Experience Version 21.1
Oracle ≫ Communications Application Session Controller Version 3.9m0p3
Oracle ≫ Communications Metasolv Solution Version 6.3.0
Oracle ≫ Communications Metasolv Solution Version 6.3.1
Oracle ≫ Communications Offline Mediation Controller Version 12.0.0.3.0
Oracle ≫ Enterprise Repository Version 11.1.1.7.0
Oracle ≫ Flexcube Universal Banking Version >= 14.1.0 <= 14.4.0
Oracle ≫ Fusion Middleware Mapviewer Version 12.2.1.4.0
Oracle ≫ Instantis Enterprisetrack Version 17.1
Oracle ≫ Instantis Enterprisetrack Version 17.2
Oracle ≫ Instantis Enterprisetrack Version 17.3
Oracle ≫ Insurance Policy Administration Version >= 11.0 <= 11.3.1
Oracle ≫ Product Lifecycle Analytics Version 3.6.1
Oracle ≫ Retail Back Office Version 14.1
Oracle ≫ Retail Central Office Version 14.1
Oracle ≫ Retail Order Broker Version 15.0
Oracle ≫ Retail Order Broker Version 16.0
Oracle ≫ Retail Order Management System Cloud Service Version 19.5
Oracle ≫ Retail Point-of-service Version 14.1
Oracle ≫ Retail Returns Management Version 14.1
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Oracle ≫ Weblogic Server Version 14.1.1.0.0
Debian ≫ Debian Linux Version 10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 13.64% | 0.96 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
|
| NIST | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://xmlgraphics.apache.org/security.html
https://security.gentoo.org/glsa/202401-11
https://lists.apache.org/thread.html/r2877ae10e8be56a3c52d03e373512ddd32f16b863f24c2e22f5a5ba2%40%3Cdev.poi.apache.org%3E
https://lists.apache.org/thread.html/r588d05a0790b40a0eb81088252e1e8c1efb99706631421f17038eb05%40%3Cdev.poi.apache.org%3E
https://lists.debian.org/debian-lts-announce/2023/10/msg00021.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEDID4DAVPECE6O4QQCSIS75BLLBUUAM/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7EAYO5XIHD6OIEA3HPK64UDDBSLNAC5/
https://lists.debian.org/debian-lts-announce/2025/07/msg00006.html