CVE-2018-8013

Description

In Apache Batik 1.x before 1.10, when deserializing subclass of AbstractDocument, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.328

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-8013 are fixed in Apache-batik 1.10Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 20.0.0.2Windows
Multiple Vulnerabilities are affected in JD Edwards EnterpriseOne Tools 9.2Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 21.0.3.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 22.0.2Windows
SVG Library (USN-3280-1) libbatik-java_1.7.ubuntu-8ubuntu2.14.04.3_all.debLinux
SVG Library (USN-3661-1) libbatik-java_1.7.ubuntu-8ubuntu2.14.04.3_all.debLinux
Vulnerabilities CVE-2018-8013 are fixed in Apache-batik for Linux 1.10Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234