CVE-2020-11987

Description

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Risk Information

Base Score
8.2
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS Score
Exploitation Probability
1.358

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.3.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.4.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 14.1.1.0.0Windows
Vulnerabilities CVE-2020-11987 are fixed in Apache-batik-svgbrowser 1.14Windows
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-base-5.14.21-150400.24.49.3.150400.24.19.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-debuginfo-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-debugsource-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-devel-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-devel-debuginfo-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Development Tools Module 15-SP4 ) kernel-obs-build-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Development Tools Module 15-SP4 ) kernel-obs-build-debugsource-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Development Tools Module 15-SP4 ) kernel-syms-5.14.21-150400.24.49.4.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Legacy Module 15-SP4 ) reiserfs-kmp-default-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Legacy Module 15-SP4 ) reiserfs-kmp-default-debuginfo-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-devel-5.14.21-150400.24.49.4.noarch.rpmLinux
SUSE-SU-2023:0796-1(Development Tools Module 15-SP4 ) kernel-docs-5.14.21-150400.24.49.4.noarch.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-macros-5.14.21-150400.24.49.4.noarch.rpmLinux
SUSE-SU-2023:0796-1(Development Tools Module 15-SP4 ) kernel-source-5.14.21-150400.24.49.4.noarch.rpmLinux
SVG Library (USN-6117-1) libbatik-java_1.10-2~18.04.1_all.debLinux
SVG Library (USN-6117-1) libbatik-java_1.12-1ubuntu0.1_all.debLinux
SVG Library (USN-6117-1) libbatik-java_1.14-1ubuntu0.2_all.debLinux
SVG Library (USN-6117-1) libbatik-java_1.14-2ubuntu0.1_all.debLinux
batik Security Update (ALAS-2023-1966) batik-1.8-0.12.svn1230816.amzn2.0.1.noarch.rpmLinux
batik Security Update (ALAS-2023-1966) batik-demo-1.8-0.12.svn1230816.amzn2.0.1.noarch.rpmLinux
batik Security Update (ALAS-2023-1966) batik-svgpp-1.8-0.12.svn1230816.amzn2.0.1.noarch.rpmLinux
batik Security Update (ALAS-2023-1966) batik-javadoc-1.8-0.12.svn1230816.amzn2.0.1.noarch.rpmLinux
batik Security Update (ALAS-2023-1966) batik-ttf2svg-1.8-0.12.svn1230816.amzn2.0.1.noarch.rpmLinux
batik Security Update (ALAS-2023-1966) batik-squiggle-1.8-0.12.svn1230816.amzn2.0.1.noarch.rpmLinux
batik Security Update (ALAS-2023-1966) batik-slideshow-1.8-0.12.svn1230816.amzn2.0.1.noarch.rpmLinux
batik Security Update (ALAS-2023-1966) batik-rasterizer-1.8-0.12.svn1230816.amzn2.0.1.noarch.rpmLinux
Vulnerabilities CVE-2020-11987 are fixed in Apache-batik-svgbrowser for Linux 1.14Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234